Encryption

HP ThinPro vulnerability allows physical attackers to bypass disk encryption

PALO ALTO, CALIFORNIA – OCTOBER 04: The Hewlett Packard (HP) logo is displayed in front of the office complex on October 04, 2019 in Palo Alto, California. HP announced plans to cut 7,000 to 9,000 jobs in an effort to save about $1 billion by the end of fiscal 2022. (Photo by Justin Sullivan/Getty Images)

A vulnerability in HP ThinPro 8 and 9 operating systems allows attackers with physical access to bypass TPM-backed full-disk encryption and recover the key securing the device's root partition. The zero-day vulnerability remained unpatched when security researcher Darren McDonald disclosed it on August 8, as reported by Cyber Insider.

The flaw, discovered by McDonald in early 2026, lies in how the Trusted Platform Module (TPM) verifies boot chain measurements before releasing the LUKS encryption key. HP ThinPro's TPM policy includes measurements for the BIOS, option ROMs, and GRUB bootloader, but omits measurements for the Linux kernel and initramfs. This gap allows an attacker with physical access to modify the initramfs, specifically a script that copies the disk encryption key to the unencrypted boot partition. After modifying the script and reinstalling the storage drive, the TPM releases the legitimate key, allowing the system to boot normally. The attacker can then retrieve the raw LUKS key from the boot partition and decrypt the protected data offline.

This vulnerability affects HP t530 and t540 devices running ThinPro 8 and 9. Organizations using ThinPro should not rely solely on full-disk encryption for data protection if devices leave their control. Recommendations include enabling Secure Boot, setting a BIOS password, and securely destroying or erasing storage media for retired devices.

Source: Cyber Insider

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds