PT-2026-71068 · Cryptopro · Cryptopro Secure Disk For Bitlocker

CVE-2025-59320

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CryptoPro Secure Disk for Bitlocker versions prior to 7.7.4
Description The software stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information to craft an environment that unseals the TPM (Trusted Platform Module), which is a specialized chip used to secure hardware through integrated cryptographic keys.
Recommendations Update to version 7.7.4 or later.

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59320

Affected Products

Cryptopro Secure Disk For Bitlocker