Vulnerability Details CVE-2025-0287
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.6%
CVSS Severity
CVSS v3 Score 5.1
Products affected by CVE-2025-0287
-
cpe:2.3:a:paragon-software:paragon_backup_&_recovery:*
-
cpe:2.3:a:paragon-software:paragon_disk_wiper:*
-
cpe:2.3:a:paragon-software:paragon_drive_copy:*
-
cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*
-
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*
-
cpe:2.3:a:paragon-software:paragon_partition_manager:*