Skip to finding
important · Boot chain

A crafted partition can redirect CryptoPro into attacker-controlled preboot code.

Affects

CryptoPro Secure Disk, preboot authentication and disk-encryption software used on Windows and embedded systems, including some ATM security deployments.

CryptoPro selects the first partition with a hardcoded type instead of certifying that it is the intended partition.

Detail and 2 sources

We do not know whether the minimum starting position is offline physical access, an already privileged host process or either one.

A patch is available and is assessed to remove this partition-selection capability.

Chain to watch
Alter the protected disk's partition layout→↓Place a crafted Linux partition before the intended CryptoPro partition→↓Let type-and-index selection boot attacker-controlled code→↓The minimum position needed to insert the partition is not stated consistently in the readable public record.
Unverified chainRetrieve the Black Hat paper or demonstration slides and identify whether the demonstrated chain starts with offline disk access, an already privileged host process or both.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026