CVE Vulnerabilities

CVE-2025-0287

NULL Pointer Dereference

Published: Mar 03, 2025 | Modified: Apr 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Potential Mitigations

References