nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-0289 CVE-2025-0289
HIGHRansomware
CVE-2025-0289
Record summary
CVE-2025-0289 has a selected CVSS score of 7.8 (high). VulnCheck reports CVE-2025-0289 use in known ransomware campaigns.
Description
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 28, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2025 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Backup and RecoveryBrowse Paragon Software / Backup and Recovery | CVE List | 15 to ≤ 17.39 | affected |
Disk WiperBrowse Paragon Software / Disk Wiper | CVE List | 15 to ≤ 16 | affected |
Drive CopyBrowse Paragon Software / Drive Copy | CVE List | 15 to ≤ 16 | affected |
Hard Disk ManagerBrowse Paragon Software / Hard Disk Manager | CVE List | 15 to ≤ 17.39 | affected |
Migrate OS to SSDBrowse Paragon Software / Migrate OS to SSD | CVE List | 4 to ≤ 5 | affected |
Partition ManagerBrowse Paragon Software / Partition Manager | VulnCheck, CVE List | 15 to ≤ 17.39 | affected |
References
4paragon-software.zendesk.com
https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys kb.cert.org
https://www.kb.cert.org/vuls/id/726882 paragon-software.com
https://www.paragon-software.com/support