CVE-2025-59320Medium· 4.6▾ SunlitCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-10041Medium· 4.7A vulnerability was found in PAM
CVE-2026-26152High· 7.0Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-84283Medium· 6.8Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree
CVE-2026-77875Medium· 6.8The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary
CVE-2026-44629High· 7.9Improper access control to the Synergis Softwire installation folder
CVE-2025-2241High· 8.2A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM)