CVE-2025-0287

MEDIUM EXPLOITED RANSOMWARE

Paragon Software - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-0287 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.

Description

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

Scores

CVSS v3 5.1
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-06-05
Ransomware Use Confirmed
CWE
CWE-476
Status published
Products (6)
paragon-software/paragon_backup_\&_recovery 15 - 17.39
paragon-software/paragon_disk_wiper 15 - 16
paragon-software/paragon_drive_copy 15 - 16
paragon-software/paragon_hard_disk_manager 15 - 17.39
paragon-software/paragon_migrate_os_to_ssd 4 - 5
paragon-software/paragon_partition_manager 15 - 17.39
Published Mar 03, 2025
Tracked Since Feb 18, 2026