CVE-2025-59320CWE-922
CVE-2025-59320
Medium · published August 12, 2026
What it is
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
The record
Technical detail
- CVSS v3.1
- 4.6 · MEDIUM
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00181 · 7.8th percentile
- Weakness
- CWE-922 · Insecure Storage of Sensitive Information
- Published
- 2026-08-12T19:17Z
References (3)
EPSS history
Timeline