CVE Vulnerabilities

CVE-2025-0287

NULL Pointer Dereference

Published: Mar 03, 2025 | Modified: Jun 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Paragon_backup_&_recoveryParagon-software15 (including)17.39 (including)
Paragon_disk_wiperParagon-software15 (including)16 (including)
Paragon_drive_copyParagon-software15 (including)16 (including)
Paragon_hard_disk_managerParagon-software15 (including)17.39 (including)
Paragon_migrate_os_to_ssdParagon-software4 (including)5 (including)
Paragon_partition_managerParagon-software15 (including)17.39 (including)

Potential Mitigations

References