PT-2026-71068 · Cryptopro · Cryptopro Secure Disk For Bitlocker
CVE-2025-59320
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CryptoPro Secure Disk for Bitlocker versions prior to 7.7.4
Description
The software stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information to craft an environment that unseals the TPM (Trusted Platform Module), which is a specialized chip used to secure hardware through integrated cryptographic keys.
Recommendations
Update to version 7.7.4 or later.
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cryptopro Secure Disk For Bitlocker