CVE-2025-0287
03.03.2025, 17:15
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.Enginsight
Vendor | Product | Version |
---|---|---|
paragon-software | paragon_backup_\&_recovery | 15 ≤ 𝑥 ≤ 17.39 |
paragon-software | paragon_disk_wiper | 15 ≤ 𝑥 ≤ 16 |
paragon-software | paragon_drive_copy | 15 ≤ 𝑥 ≤ 16 |
paragon-software | paragon_hard_disk_manager | 15 ≤ 𝑥 ≤ 17.39 |
paragon-software | paragon_migrate_os_to_ssd | 4 ≤ 𝑥 ≤ 5 |
paragon-software | paragon_partition_manager | 15 ≤ 𝑥 ≤ 17.39 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration