漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Integrity Validation Bypass in CryptoPro Secure Disk for BitLocker
Vulnerability Description
The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system is located on a separate unencrypted partition which can be reached by anyone with access to the hard disk. Multiple checks are performed to validate the integrity of the Linux operating system and the CryptoPro Secure Disk application files. When files are changed an error is shown on system start. One of the checks is the Linux kernel's Integrity Measurement Architecture (IMA). It was identified that configuration files are not validated by the IMA and can then (if not checked by other measures) be changed. This allows an attacker to execute arbitrary code in the context of the root user and enables an attacker to e.g., plant a backdoor and access data during execution.
CVSS Information
N/A
Vulnerability Type
缺失完整性检查支持
Vulnerability Title
CPSD CryptoPro Secure Disk 安全漏洞
Vulnerability Description
CPSD CryptoPro Secure Disk是CPSD公司的一个透明磁盘加密软件。 CPSD CryptoPro Secure Disk存在安全漏洞,该漏洞源于Linux操作系统完整性检查中配置文件未经过完整性测量架构验证,可能导致攻击者以root用户上下文执行任意代码,例如植入后门并在执行期间访问数据。
CVSS Information
N/A
Vulnerability Type
N/A