Nine vulnerabilities in CryptoPro Secure Disk allowed you to bypass security checks even before Windows is launched, get to TPM secrets and in separate scenarios execute code with high privileges. The problem went far beyond conventional computers: vulnerabilities affected software that is used to protect ATMs, among other things.
CryptoPro Secure Disk releases German CryptWare IT Security. The product complements BitLocker with its own pre-boot authentication and other protection mechanisms, and the Enterprise version also knows how to independently perform full disk encryption with AES-256. CryptWare offers a solution for laptops, desktops and ATMs.
Atredis Partners researcher Matt Burch has dismantled the internal architecture of CryptoPro Secure Disk and found several ways to violate the established model of trust. The program could choose a front Linux partition instead of the expected, stored data to work with a trusted platform module in the disk sectors available for physical analysis, and the TPM policy did not always link the disclosure of secrets to the real state of the system loading. Other errors affected LUKS checks, the integrity of the Internal DataStore and the running of the code from the time file system.
One of the most dangerous problems, CVE-2025-59326, allowed you to run unsigned code from temporary file systems, since CryptoPro Secure Disk did not distribute Linux Integrity Measurement Architecture’s security policy to them. Together, the weaknesses found allowed the researcher to recover cryptographic data, bypass part of integrity checks, and interfere with the secure loading chain.
CryptWare received the first notice of the study in the summer of 2025. The company released CryptoPro 7.7.2 in November, 7.7.3 in December and 7.7.4 in February 2026. By the end of April, Burch had checked the fixes and confirmed that the vulnerabilities he had found were closed. CryptWare management said the product is used by hundreds of customers from the banking sector, auto industry, government organizations, manufacturing, finance, healthcare and other industries.
ATM manufacturer Diebold Nixdorf reported that only two of the nine problems found were important for the Vynamic Security Hard Disk Encryption complex. The company distributed its own corrections in December and claims that two vulnerabilities themselves did not allow the ATM to be compromised.
CryptoPro Secure Disk releases German CryptWare IT Security. The product complements BitLocker with its own pre-boot authentication and other protection mechanisms, and the Enterprise version also knows how to independently perform full disk encryption with AES-256. CryptWare offers a solution for laptops, desktops and ATMs.
Atredis Partners researcher Matt Burch has dismantled the internal architecture of CryptoPro Secure Disk and found several ways to violate the established model of trust. The program could choose a front Linux partition instead of the expected, stored data to work with a trusted platform module in the disk sectors available for physical analysis, and the TPM policy did not always link the disclosure of secrets to the real state of the system loading. Other errors affected LUKS checks, the integrity of the Internal DataStore and the running of the code from the time file system.
One of the most dangerous problems, CVE-2025-59326, allowed you to run unsigned code from temporary file systems, since CryptoPro Secure Disk did not distribute Linux Integrity Measurement Architecture’s security policy to them. Together, the weaknesses found allowed the researcher to recover cryptographic data, bypass part of integrity checks, and interfere with the secure loading chain.
CryptWare received the first notice of the study in the summer of 2025. The company released CryptoPro 7.7.2 in November, 7.7.3 in December and 7.7.4 in February 2026. By the end of April, Burch had checked the fixes and confirmed that the vulnerabilities he had found were closed. CryptWare management said the product is used by hundreds of customers from the banking sector, auto industry, government organizations, manufacturing, finance, healthcare and other industries.
ATM manufacturer Diebold Nixdorf reported that only two of the nine problems found were important for the Vynamic Security Hard Disk Encryption complex. The company distributed its own corrections in December and claims that two vulnerabilities themselves did not allow the ATM to be compromised.