logo

DataArmor FDE Breakout & Privilege Escalation

ID: cba5559c-2f45-51ac-a9e0-881ea4e36f6b

STIX ID: report--cba5559c-2f45-51ac-a9e0-881ea4e36f6b

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-07-31

...
...

DataArmor Full Disk Encryption (versions prior to v3.0.12.861) contains a critical local vulnerability that allows an attacker with physical access to use the Linux Magic SysRq key to break out of the product's restricted X11 environment into a BusyBox root shell, modify authentication and policy files to add/escalate users, recover or fully decrypt the encrypted partition, and exfiltrate sensitive data; vendor fixes and mitigations (disable SysRq, recompile kernel, strip BusyBox utilities) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.