First published: Mon Mar 03 2025(Updated: )
Paragon Partition Manager version 7.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paragon Partition Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0287 has a high severity due to its potential for privilege escalation through arbitrary code execution in the kernel.
To mitigate CVE-2025-0287, update Paragon Partition Manager to the latest version that contains the security patch addressing this vulnerability.
Paragon Partition Manager version 7.9.1 is specifically affected by CVE-2025-0287.
CVE-2025-0287 is a null pointer dereference vulnerability that can lead to kernel-level arbitrary code execution.
Exploitation of CVE-2025-0287 typically requires local access to the affected system, as it involves a kernel-level vulnerability.