CVE-2025-0289: High severity paragon software various products vulnerability
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0289?
CVE-2025-0289 is classified as a high severity vulnerability due to the potential for exploitation that could lead to unauthorized access or system compromise.
How do I fix CVE-2025-0289?
To fix CVE-2025-0289, update to the latest version of Paragon Partition Manager that includes the security patch for the identified vulnerability.
What versions of Paragon Partition Manager are affected by CVE-2025-0289?
CVE-2025-0289 affects both the community and business versions of Paragon Partition Manager version 17.
What type of vulnerability is CVE-2025-0289?
CVE-2025-0289 is an insecure kernel resource access vulnerability that allows attackers to exploit the driver’s mismanagement of the MappedSystemVa pointer.
Who can be impacted by CVE-2025-0289?
Users and organizations utilizing Paragon Partition Manager version 17 are at risk of being impacted by CVE-2025-0289 if they do not apply the necessary security updates.