CVE-2025-59320

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.

Published 2026-08-12. Last modified 2026-09-29.