important · Physical — Disk encryption
A physical attacker can recover CryptoPro's on-disk TPM secrets and unseal protected disk material elsewhere.
Affects
CryptoPro Secure Disk for BitLocker, preboot authentication and disk-encryption software deployed on Windows systems, embedded devices, and some ATM platforms.
The attacker must be able to image or relocate the disk. Serialized TPM secrets in unused sectors then combine with an insufficient PCR policy to permit unsealing outside the intended state.
Detail and 3 sources
The researcher reported validating the vendor's fixes.