CVE-2025-0287: Null Pointer Dereference
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0287?
CVE-2025-0287 has a high severity due to its potential for privilege escalation through arbitrary code execution in the kernel.
How do I fix CVE-2025-0287?
To mitigate CVE-2025-0287, update Paragon Partition Manager to the latest version that contains the security patch addressing this vulnerability.
Which version of Paragon Partition Manager is affected by CVE-2025-0287?
Paragon Partition Manager version 7.9.1 is specifically affected by CVE-2025-0287.
What type of vulnerability is CVE-2025-0287?
CVE-2025-0287 is a null pointer dereference vulnerability that can lead to kernel-level arbitrary code execution.
Can CVE-2025-0287 be exploited remotely?
Exploitation of CVE-2025-0287 typically requires local access to the affected system, as it involves a kernel-level vulnerability.