First published: Mon Mar 03 2025(Updated: )
Paragon Partition Manager version 17, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paragon Partition Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0289 is classified as a high severity vulnerability due to the potential for exploitation that could lead to unauthorized access or system compromise.
To fix CVE-2025-0289, update to the latest version of Paragon Partition Manager that includes the security patch for the identified vulnerability.
CVE-2025-0289 affects both the community and business versions of Paragon Partition Manager version 17.
CVE-2025-0289 is an insecure kernel resource access vulnerability that allows attackers to exploit the driver’s mismanagement of the MappedSystemVa pointer.
Users and organizations utilizing Paragon Partition Manager version 17 are at risk of being impacted by CVE-2025-0289 if they do not apply the necessary security updates.