CVE-2025-0287

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
certccCNA
---
---
CISA-ADPADP
5.1 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
paragon-softwareparagon_backup_\&_recovery
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_disk_wiper
15 ≤
𝑥
≤ 16
paragon-softwareparagon_drive_copy
15 ≤
𝑥
≤ 16
paragon-softwareparagon_hard_disk_manager
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_migrate_os_to_ssd
4 ≤
𝑥
≤ 5
paragon-softwareparagon_partition_manager
15 ≤
𝑥
≤ 17.39
𝑥
= Vulnerable software versions