CVE-2025-0286

Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
certccCNA
---
---
CISA-ADPADP
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
paragon-softwareparagon_backup_\&_recovery
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_disk_wiper
15 ≤
𝑥
≤ 16
paragon-softwareparagon_drive_copy
15 ≤
𝑥
≤ 16
paragon-softwareparagon_hard_disk_manager
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_migrate_os_to_ssd
4 ≤
𝑥
≤ 5
paragon-softwareparagon_partition_manager
15 ≤
𝑥
≤ 17.39
𝑥
= Vulnerable software versions