Researcher Matt Burch of Atredis Partners disclosed nine vulnerabilities in CryptWare CryptoPro Secure Disk, a Windows full-disk encryption and pre-boot authentication product used in enterprise environments and integrated into some ATM security stacks. The flaws affect pre-boot decryption handling, storage of sensitive key material and configuration data on disk, and Secure Boot implementation, potentially allowing plaintext mounting of encrypted volumes, recovery of decryption keys, and arbitrary Linux execution before the operating system loads.
Burch said the weaknesses could enable ATM jackpotting in some scenarios, but Diebold Nixdorf disputed the practical impact on its ATM deployments. The vendor said it does not use BitLocker, that only two of the nine issues were theoretically applicable to its hard-disk encryption under certain conditions, and that those issues appear to have been addressed in a December 2025 update to components used in its Vynamic Security Suite. Beyond the ATM dispute, the findings highlight broader risk for organizations using CryptoPro across Windows fleets, where poorly protected cryptographic secrets could undermine disk-encryption protections.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CryptWare CryptoPro Secure Disk vulnerability research was scheduled for presentation at Black Hat USA 2026.
Matt Burch of Atredis Partners disclosed nine vulnerabilities in CryptWare CryptoPro Secure Disk, including weaknesses that could allow plaintext mounting of encrypted volumes, exposure of key material on disk, and arbitrary pre-boot code execution. He said the flaws could potentially enable ATM jackpotting scenarios, while Diebold Nixdorf disputed the practical impact on its ATM deployments.
Diebold Nixdorf said two of the nine CryptWare CryptoPro Secure Disk issues were theoretically applicable to its hard disk encryption under certain conditions and appeared to have been addressed in a December 2025 update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.