• News/
  • https://www.bleepingcomputer.com/news/security/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/

Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks

BleepingComputer
·
Bill Toulas
·
Published Mar 1, 2025
·
Updated

Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. The vulnerable drivers were exploited in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks where threat actors drop the kernel driver on a targeted system to elevate privileges. "An attacker with local access to a device can exploit these vulnerabilities to escalate privileges or cause a denial-of-service (DoS) scenario on the victim's machine," explains a warning from CERT/CC. "Additionally, as the attack involves a Microsoft-signed Driver, an attacker can leverage a Bring Your Own Vulnerable Driver (BYOVD) technique to exploit systems even if Paragon Partition Manager is not installed. " As BioNTdrv.sys is a kernel-level driver, threat actors can exploit vulnerabilities to execute commands with the same privileges as the driver, bypassing protections and security software. Microsoft researchers discovered all five flaws, noting that one of them, CVE-2025-0289, is leveraged in attacks by ransomware groups. However, the researchers did not disclose what ransomware gangs were exploiting the flaw as a zero-day. "Microsoft has observed threat actors (TAs) exploiting this weakness in BYOVD ransomware attacks, specifically using CVE-2025-0289 to achieve privilege escalation to SYSTEM level, then execute further malicious code," reads the CERT/CC bulletin. "These vulnerabilities have been patched by both Par...

Read full article

Affected Software

7 affected components
Paragon Software Paragon Partition Manager=7.9.1
Paragon Software Paragon Partition Manager
Paragon Software Paragon Partition Manager=17
Paragon Software BioNTdrv.sys
Paragon Software BioNTdrv.sys=2.0.0
Paragon Partition Manager
Microsoft Windows
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how ransomware gangs are exploiting vulnerabilities in Paragon Partition Manager to conduct attacks.

2

What specific vulnerability is being exploited by ransomware gangs?

Ransomware actors are exploiting a bug in the BioNTdrv.sys driver of Paragon Partition Manager to gain SYSTEM privileges.

3

What versions of Paragon Partition Manager are affected?

The affected versions of Paragon Partition Manager include 7.9.1 and 17.

4

What are the potential security implications of this exploitation?

The exploitation allows attackers to elevate privileges and potentially gain full control over affected Windows systems.

5

What software or drivers are impacted by this security issue?

The Paragon Partition Manager and its BioNTdrv.sys driver are the key affected software in this security vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203