CVE-2022-34301

MEDIUM

CryptoPro Secure Disk <2022-06-01 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

Scores

CVSS v3 6.7
EPSS 0.0013
EPSS Percentile 31.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (19)
kidan/cryptopro_securedisk_for_bitlocker < 2022-06-01
microsoft/windows_10
microsoft/windows_10 20h2
microsoft/windows_10 21h1
microsoft/windows_10 21h2
microsoft/windows_10 1607
microsoft/windows_10 1809
microsoft/windows_11
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 9 more
Published Aug 26, 2022
Tracked Since Feb 18, 2026