7.8

CVE-2025-0288

CVE-2025-0288

Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paragon-software ≫ Paragon Disk Wiper Version >= 15 <= 16
Paragon-software ≫ Paragon Drive Copy Version >= 15 <= 16
Paragon-software ≫ Paragon Hard Disk Manager Version >= 15 <= 17.39
Paragon-software ≫ Paragon Partition Manager Version >= 15 <= 17.39
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.393
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys
Vendor Advisory
https://www.kb.cert.org/vuls/id/726882
Third Party Advisory
https://www.paragon-software.com/support/#patches
Product