CVE-2025-0285
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2025
Last modified:
25/06/2025
Description
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:* | 15 (including) | 17.39 (including) |
| cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:* | 15 (including) | 16 (including) |
| cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:* | 15 (including) | 16 (including) |
| cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:* | 15 (including) | 17.39 (including) |
| cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:* | 4 (including) | 5 (including) |
| cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:* | 15 (including) | 17.39 (including) |
To consult the complete list of CPE names with products and versions, see this page



