CVE-2025-0286
03.03.2025, 17:15
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.Enginsight
Vendor | Product | Version |
---|---|---|
paragon-software | paragon_backup_\&_recovery | 15 ≤ 𝑥 ≤ 17.39 |
paragon-software | paragon_disk_wiper | 15 ≤ 𝑥 ≤ 16 |
paragon-software | paragon_drive_copy | 15 ≤ 𝑥 ≤ 16 |
paragon-software | paragon_hard_disk_manager | 15 ≤ 𝑥 ≤ 17.39 |
paragon-software | paragon_migrate_os_to_ssd | 4 ≤ 𝑥 ≤ 5 |
paragon-software | paragon_partition_manager | 15 ≤ 𝑥 ≤ 17.39 |
𝑥
= Vulnerable software versions