CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cpsd
Cpsd cryptopro Secure Disk |
|
| Vendors & Products |
Cpsd
Cpsd cryptopro Secure Disk |
Wed, 12 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | TPM Secret Exposure via Unused Disk Sectors in CryptoPro Secure Disk for Bitlocker |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-922 | |
| Metrics |
cvssV3_1
|
Wed, 12 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-12T19:26:22.530Z
Reserved: 2025-09-12T00:00:00.000Z
Link: CVE-2025-59320
No data.
Status : Received
Published: 2026-08-12T15:17:29.787
Modified: 2026-08-12T20:17:32.960
Link: CVE-2025-59320
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:45:02Z