HP ThinPro bug can let attackers steal encrypted data
HP ThinPro 8 and 9 have a security flaw that lets attackers with physical access steal encrypted data from thin clients. The issue lets attackers bypass the device's built-in encryption protection.
- Report priority
- Medium
- Involves
- Microsoft
What is known
Attackers modify the unencrypted initramfs file, which holds the script that unlocks the encrypted disk, without triggering the TPM's security checks.
What to do
Check if you use HP ThinPro 8 or 9 on a thin client with LUKS2 encryption enabled for the root partition.
Update to HP ThinPro 10 or later, which fixes this TPM validation gap, or disable LUKS2 encryption if you cannot upgrade.
Reported details
An attacker steals a ThinPro 8 thin client and replaces its initramfs file with a modified version. During boot, the device's TPM checks only the BIOS, bootloader, and drivers, not the initramfs script. The attacker's script steals the LUKS encryption key from the TPM and sends it to a remote server. The attacker now has full access to the device's encrypted data.
This vulnerability in outdated HP ThinPro versions (build 22) and the latest version (build 15) exposes encrypted data on affected thin clients when an attacker has physical access. The flaw lies in how the Trusted Platform Module (TPM) enforces LUKS disk encryption: while the TPM seals the decryption key to BIOS, UEFI drivers, and GRUB, it fails to validate the unencrypted initramfs or the Linux kernel. An attacker can modify the unseal_key script in initramfs to copy the LUKS key to the unencrypted BOOT partition during boot, bypassing TPM checks.
Once the device reboots normally, the attacker can extract the key from the storage drive, granting access to encrypted partitions containing configuration data, certificates, credentials, and password hashes. The issue was reported by AmberWolf under identifier NEWS-8a93580d1e60b5b853.
References
- blog.amberwolf.com · hp-thinpro-tpm-sealed-disk-encryption-that-only-measured-half-the-boot-chain Cyber Security News
- any.run · enterprise Cyber Security News
- securityaffairs.com · security-affairs-malware-newsletter-round-109.html SecurityAffairs
- bitdefender.com · fake-xeno-roblox-discord-executor SecurityAffairs
- censys.com · darkswords-panel-sprawl SecurityAffairs
- socket.dev · npm-rat-targets-alibaba SecurityAffairs
- securonix.com · smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels SecurityAffairs
- unit42.paloaltonetworks.com · xcsset-v40-malware-analysis SecurityAffairs
- socradar.io · doublecup-clickfix-loader-devicemanager-rats SecurityAffairs
- opensourcemalware.com · russian-ai-slopsquatting-npm-campaign SecurityAffairs
- huntress.com · mac-crypto-draining-malware SecurityAffairs
- arxiv.org · 2608.03642 (2608.03642) SecurityAffairs
- objective-see.org · ransomwhere.html SecurityAffairs
- arxiv.org · 2608.03250 (2608.03250) SecurityAffairs
- mdpi.com · 504 SecurityAffairs
- mdpi.com · 2759 SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- thehackernews.com · nearly-800-malicious-npm-packages.html TheHackerNews
- darkreading.com · latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook DarkReading
- stepsecurity.io · joyfill-npm-supply-chain-compromise StepSecurity
- securityonline.info · interlock-ransomware-volatility3 SecurityOnline
- securityonline.info · greatness-phaas-aitm-phishing SecurityOnline
- securityonline.info · smoke-screen-screenconnect-rmm SecurityOnline
- gbhackers.com · github-expands-dependabot-malware-alerts GBHackers
- gbhackers.com · fake-solidity-pro-extensions GBHackers