CVE-2025-0289

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
certccCNA
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
paragon-softwareparagon_backup_\&_recovery
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_disk_wiper
15 ≤
𝑥
≤ 16
paragon-softwareparagon_drive_copy
15 ≤
𝑥
≤ 16
paragon-softwareparagon_hard_disk_manager
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_migrate_os_to_ssd
4 ≤
𝑥
≤ 5
paragon-softwareparagon_partition_manager
15 ≤
𝑥
≤ 17.39
𝑥
= Vulnerable software versions