Skip to finding
important · Physical — Disk encryption

A physical attacker can recover CryptoPro's on-disk TPM secrets and unseal protected disk material elsewhere.

Affects

CryptoPro Secure Disk for BitLocker, preboot authentication and disk-encryption software deployed on Windows systems, embedded devices, and some ATM platforms.

The attacker must be able to image or relocate the disk. Serialized TPM secrets in unused sectors then combine with an insufficient PCR policy to permit unsealing outside the intended state.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026