← Browse

CVE-2025-59321

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.8%
53.9th percentile
CISA KEV
Not listed
Weakness / dates
CWE-1188
Published 2026-08-12 · modified 2026-08-31

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

References

Official: NVD · CVE.org