VulnerabilityAnalyzed
CVE-2025-0287
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel,…
MEDIUM 5.1EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
- CVSS 3.1
- 5.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- paragon-software/paragon backup \& recovery · paragon-software/paragon disk wiper · paragon-software/paragon drive copy · paragon-software/paragon hard disk manager · paragon-software/paragon migrate os to ssd · paragon-software/paragon partition manager
- Source
- cret@cert.org
References
- https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sysVendor Advisory
- https://www.kb.cert.org/vuls/id/726882Third Party Advisory
- https://www.paragon-software.com/support/#patchesProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.