Physical root code execution via unchecked DHCP hook
Published Feb 24, 2026 · Updated Feb 24, 2026
Integrity validation bypass in CryptoPro Secure Disk for BitLocker before 7.6.6 allows physically proximate attackers to execute code as root. The Linux pre-boot environment leaves /etc/dhcpcd.enter-hook outside IMA validation, so dhcpcd executes attacker-written Bash hooks as root. Exploitation requires physical disk access by booting external media or removing and mounting the drive; the resulting root code can implant a backdoor and access data during operation.
Summary
What happened
Integrity validation bypass in CryptoPro Secure Disk for BitLocker before 7.6.6 allows physically proximate attackers to execute code as root. The Linux pre-boot environment leaves /etc/dhcpcd.enter-hook outside IMA validation, so dhcpcd executes attacker-written Bash hooks as root. Exploitation requires physical disk access by booting external media or removing and mounting the drive; the resulting root code can implant a backdoor and access data during operation.
The record
- CVE
- CVE-2025-10010
- Published
- Feb 24, 2026
- Updated
- Feb 24, 2026
- Vendor
- CryptWare IT Security GmbH
- Product
- CryptoPro Secure Disk for BitLocker
- Classifications
- CWE-353, T1542.003
- Attack vector
- physical
- Privileges
- unauthenticated
Timeline
How it unfolded
- Feb 24, 2026CVE publishedPublication date reported by the CVE source.
- Feb 24, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=<7.6.6 / 7.7.1
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- SEC Consult DHCP enter-hook reverse-shell proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo