Record summary

CVE-2025-0289 has a selected CVSS score of 7.8 (high). VulnCheck reports CVE-2025-0289 use in known ransomware campaigns.

Description

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2025 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus
CVE List15 to ≤ 17.39affected
CVE List15 to ≤ 16affected
CVE List15 to ≤ 16affected
CVE List15 to ≤ 17.39affected
CVE List4 to ≤ 5affected
VulnCheck, CVE List15 to ≤ 17.39affected

References

4