CVE-2025-0288: High severity paragon software vulnerability
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0288?
CVE-2025-0288 is considered a critical severity vulnerability due to its potential for privilege escalation via arbitrary kernel memory writes.
How do I fix CVE-2025-0288?
To fix CVE-2025-0288, users should update Paragon Partition Manager to the latest version where the vulnerability has been patched.
What type of vulnerability is CVE-2025-0288?
CVE-2025-0288 is an arbitrary kernel memory vulnerability that results from improper input validation in the memmove function.
Who is affected by CVE-2025-0288?
CVE-2025-0288 affects users of Paragon Partition Manager version 7.9.1 and potentially earlier versions.
Can CVE-2025-0288 be exploited remotely?
CVE-2025-0288 is a local privilege escalation vulnerability, requiring an authenticated user to exploit it.