Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. The vulnerable drivers were exploited in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks where threat actors drop the kernel driver on a targeted system to elevate privileges. "An attacker with local access to a device can exploit these vulnerabilities to escalate privileges or cause a denial-of-service (DoS) scenario on the victim's machine," explains a warning from CERT/CC. "Additionally, as the attack involves a Microsoft-signed Driver, an attacker can leverage a Bring Your Own Vulnerable Driver (BYOVD) technique to exploit systems even if Paragon Partition Manager is not installed. " As BioNTdrv.sys is a kernel-level driver, threat actors can exploit vulnerabilities to execute commands with the same privileges as the driver, bypassing protections and security software. Microsoft researchers discovered all five flaws, noting that one of them, CVE-2025-0289, is leveraged in attacks by ransomware groups. However, the researchers did not disclose what ransomware gangs were exploiting the flaw as a zero-day. "Microsoft has observed threat actors (TAs) exploiting this weakness in BYOVD ransomware attacks, specifically using CVE-2025-0289 to achieve privilege escalation to SYSTEM level, then execute further malicious code," reads the CERT/CC bulletin. "These vulnerabilities have been patched by both Par...
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
BleepingComputer
·Bill Toulas
·Published Mar 1, 2025
·Updated
Affected Software
7 affected components
Paragon Software Paragon Partition Manager=7.9.1
Paragon Software Paragon Partition Manager
Paragon Software Paragon Partition Manager=17
Paragon Software BioNTdrv.sys
Paragon Software BioNTdrv.sys=2.0.0
Paragon Partition Manager
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how ransomware gangs are exploiting vulnerabilities in Paragon Partition Manager to conduct attacks.
2
What specific vulnerability is being exploited by ransomware gangs?
Ransomware actors are exploiting a bug in the BioNTdrv.sys driver of Paragon Partition Manager to gain SYSTEM privileges.
3
What versions of Paragon Partition Manager are affected?
The affected versions of Paragon Partition Manager include 7.9.1 and 17.
4
What are the potential security implications of this exploitation?
The exploitation allows attackers to elevate privileges and potentially gain full control over affected Windows systems.
5
What software or drivers are impacted by this security issue?
The Paragon Partition Manager and its BioNTdrv.sys driver are the key affected software in this security vulnerability.