CVE-2025-0286

HIGH EXPLOITED RANSOMWARE

Paragon Software - Memory Corruption

Title source: llm
STIX 2.1

Description

Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.

Scores

CVSS v3 8.4
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-06-05
Ransomware Use Confirmed
CWE
CWE-1284
Status published
Products (6)
paragon-software/paragon_backup_\&_recovery 15 - 17.39
paragon-software/paragon_disk_wiper 15 - 16
paragon-software/paragon_drive_copy 15 - 16
paragon-software/paragon_hard_disk_manager 15 - 17.39
paragon-software/paragon_migrate_os_to_ssd 4 - 5
paragon-software/paragon_partition_manager 15 - 17.39
Published Mar 03, 2025
Tracked Since Feb 18, 2026