CVE-2025-0287
MEDIUM EXPLOITED RANSOMWAREParagon Software - Privilege Escalation
Title source: llmExploitation Summary
CVE-2025-0287 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.
Description
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
References (3)
Core 3
Core References
Third Party Advisory
https://www.kb.cert.org/vuls/id/726882
Scores
CVSS v3
5.1
EPSS
0.0034
EPSS Percentile
26.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2025-06-05
Ransomware Use
Confirmed
CWE
CWE-476
Status
published
Products (6)
paragon-software/paragon_backup_\&_recovery
15 - 17.39
paragon-software/paragon_disk_wiper
15 - 16
paragon-software/paragon_drive_copy
15 - 16
paragon-software/paragon_hard_disk_manager
15 - 17.39
paragon-software/paragon_migrate_os_to_ssd
4 - 5
paragon-software/paragon_partition_manager
15 - 17.39
Published
Mar 03, 2025
Tracked Since
Feb 18, 2026