Description

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

INFO

Published Date :

2025-03-03T16:25:08.481Z

Last Modified :

2025-09-05T12:08:03.175Z

Source :

certcc
AFFECTED PRODUCTS

The following products are affected by CVE-2025-0287 vulnerability.

Vendors Products
Paragon-software
  • Paragon Backup \& Recovery
  • Paragon Disk Wiper
  • Paragon Drive Copy
  • Paragon Hard Disk Manager
  • Paragon Migrate Os To Ssd
  • Paragon Partition Manager

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact