Record summary

CVE-2025-0287 has a selected CVSS score of 5.1 (medium). VulnCheck reports CVE-2025-0287 use in known ransomware campaigns.

Description

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 5, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 3, 2025 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
CVE List15 to ≤ 17.39affected
CVE List15 to ≤ 16affected
CVE List15 to ≤ 16affected
CVE List15 to ≤ 17.39affected

Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSD

Browse Paragon Software / Hard Disk Manager/Partition Manager/Backup & Recovery/Drive Copy/Disk Wiper/Migrate OS to SSD
VulnCheckVersion data not supplied
CVE List4 to ≤ 5affected
CVE List15 to ≤ 17.39affected

References

4