CVE-2025-0285: High severity paragon software various products vulnerability
Published Mar 3, 2025
·Updated
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.
Affected Software
7 affected components
Paragon Software Paragon Software products
Paragon-software Paragon Backup \& Recovery>=15<=17.39
Paragon-software Paragon Disk Wiper>=15<=16
Paragon-software Paragon Drive Copy>=15<=16
Paragon-software Paragon Hard Disk Manager>=15<=17.39
Paragon-software Paragon Migrate Os To Ssd>=4<=5
Paragon-software Paragon Partition Manager>=15<=17.39
Event History
Mar 3, 2025
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0285?
CVE-2025-0285 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2025-0285?
To address CVE-2025-0285, update to the latest version of Paragon Partition Manager which includes the security patch.
3
What causes CVE-2025-0285?
CVE-2025-0285 is caused by the improper validation of the length of user supplied data in biontdrv.sys.
4
Who is affected by CVE-2025-0285?
Any user of Paragon Partition Manager version 7.9.1 is potentially affected by CVE-2025-0285.
5
Can CVE-2025-0285 lead to system compromise?
Yes, CVE-2025-0285 can potentially lead to system compromise through privilege escalation attacks.