Paragon Software Vulnerabilities and Affected Products
Vulnerabilities associated with Drive Copy.
Products
Clear product- Backup and Recovery5 vulnerabilities
- Disk Wiper5 vulnerabilities
- Hard Disk Manager5 vulnerabilities
- Migrate OS to SSD5 vulnerabilities
- Partition Manager5 vulnerabilities
- Drive Copy4 vulnerabilities
- Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSD4 vulnerabilities
- Paragon Drive Copy1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-0286HIGH | CVE-2025-0286Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. | CVSS8.4v3.1 | EPSS0.367% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2025-0287MEDIUM | CVE-2025-0287Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation. CWE-476Mar 3, 2025 | CVSS5.1v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2025-0288HIGH | CVE-2025-0288Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation. CWE-131Mar 3, 2025 | CVSS7.8v3.1 | EPSS0.487% | PoCs2 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2025-0289HIGH | CVE-2025-0289Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. | CVSS7.8v3.1 | EPSS0.329% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |