CVE-2025-0287 Details
Description
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
A null pointer dereference vulnerability has been identified in the BioNTdrv.sys driver used by various Paragon Software products, including the Hard Disk Manager (HDM) product line. This vulnerability affects BioNTdrv.sys versions 10.1.X.Y and older, as well as specific 1.X.0.0 versions, excluding 2.0.0.0. The issue arises from the driver's failure to validate the MasterLrp structure in the input buffer, leading to a null pointer dereference. An attacker with local access can exploit this vulnerability to execute arbitrary code in the kernel, potentially escalating privileges to SYSTEM level. This vulnerability has been observed in conjunction with BYOVD ransomware attacks, where exploited drivers are used to gain elevated privileges before executing malicious code.
Users can update to Paragon Hard Disk Manager version 2.0.0, which addresses this vulnerability. Instructions for downloading the update are available on the Paragon Software Support website. Additionally, Microsoft has blocked vulnerable BioNTdrv.sys versions through its Vulnerable Driver Blocklist, which is enabled by default on Windows 11 devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| paragon-software paragon backup & recovery | >= 15, <= 17.39 |
CPE
Remediation
| |
| paragon-software paragon disk wiper | >= 15, <= 16 |
CPE
Remediation
| |
| paragon-software paragon drive copy | >= 15, <= 16 |
CPE
Remediation
| |
| paragon-software paragon hard disk manager | >= 15, <= 17.39 |
CPE
Remediation
| |
| paragon-software paragon migrate os to ssd | >= 4, <= 5 |
CPE
Remediation
| |
| paragon-software paragon partition manager | >= 15, <= 17.39 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 25, 2025 | Initial Analysis | [email protected] |
| Apr 14, 2025 | CVE Modified | [email protected] |
| Mar 27, 2025 | CVE Modified | [email protected] |
| Mar 5, 2025 | CVE Modified | [email protected] |
| Mar 3, 2025 | CVE Modified | CISA-ADP |
| Mar 3, 2025 | New CVE Received | [email protected] |