7.8
CVE-2025-0288
- EPSS 0.04%
- Veröffentlicht 03.03.2025 17:15:13
- Zuletzt bearbeitet 25.06.2025 16:49:22
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paragon-software ≫ Paragon Disk Wiper Version >= 15 <= 16
Paragon-software ≫ Paragon Drive Copy Version >= 15 <= 16
Paragon-software ≫ Paragon Hard Disk Manager Version >= 15 <= 17.39
Paragon-software ≫ Paragon Migrate Os To Ssd Version >= 4 <= 5
Paragon-software ≫ Paragon Partition Manager Version >= 15 <= 17.39
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|