CVE-2025-59320CWE-922

CVE-2025-59320

Medium · published August 12, 2026

CVSS v3.1
4.6
EPSS
0%
Percentile
7.8
In the wild
Unconfirmed
What it is

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.

The record
Technical detail
CVSS v3.1
4.6 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00181 · 7.8th percentile
Weakness
CWE-922 · Insecure Storage of Sensitive Information
Published
2026-08-12T19:17Z
References (3)
EPSS history
Timeline
  • 12 AUG 00:00Z
    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors
    cvelistv5