What is CVE-2025-59320?
CPSD CryptoPro Secure Disk for Bitlocker versions before 7.7.4 store TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. Upgrading to version 7.7.4 or later is strongly recommended.
Azərbaycanca: CPSD CryptoPro Secure Disk for Bitlocker-in 7.7.4-dən əvvəlki versiyalarında TPM2.0 sirləri istifadə olunmayan disk sektorlarında seriallaşdırılmış formatda saxlanılır. Sistem diskinə fiziki girişi olan autentifikasiya olunmamış hücumçu bu məlumatı bərpa edə və TPM-i açmaq üçün mühit yarada bilər. Zəiflikdən qorunmaq üçün proqram təminatını ən azı 7.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of CPSD CryptoPro Secure Disk for Bitlocker are affected by CVE-2025-59320?
This vulnerability affects versions before 7.7.4.
How can one protect against CVE-2025-59320?
It is recommended to upgrade the software to version 7.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.