CVE-2025-0285

HIGH EXPLOITED RANSOMWARE

Paragon Software - Privilege Escalation

Title source: llm
STIX 2.1

Description

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 28.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-06-05
Ransomware Use Confirmed
CWE
CWE-1284
Status published
Products (6)
paragon-software/paragon_backup_\&_recovery 15 - 17.39
paragon-software/paragon_disk_wiper 15 - 16
paragon-software/paragon_drive_copy 15 - 16
paragon-software/paragon_hard_disk_manager 15 - 17.39
paragon-software/paragon_migrate_os_to_ssd 4 - 5
paragon-software/paragon_partition_manager 15 - 17.39
Published Mar 03, 2025
Tracked Since Feb 18, 2026