Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Paragon_backup_&_recovery | Paragon-software | 15 (including) | 17.39 (including) |
| Paragon_disk_wiper | Paragon-software | 15 (including) | 16 (including) |
| Paragon_drive_copy | Paragon-software | 15 (including) | 16 (including) |
| Paragon_hard_disk_manager | Paragon-software | 15 (including) | 17.39 (including) |
| Paragon_migrate_os_to_ssd | Paragon-software | 4 (including) | 5 (including) |
| Paragon_partition_manager | Paragon-software | 15 (including) | 17.39 (including) |