Null Pointer Dereference Vulnerability in Paragon Partition Manager by Paragon Software
CVE-2025-0287

5.1MEDIUM

Key Information:

Vendor
CVE Published:
3 March 2025

Summary

Paragon Partition Manager version 7.9.1 is susceptible to a null pointer dereference vulnerability in the biontdrv.sys driver. This vulnerability is caused by an invalid MasterLrp structure in the input buffer, allowing attackers to exploit this flaw to execute arbitrary code within the kernel environment. Such an exploit can facilitate unauthorized privilege escalation, potentially compromising the integrity of the system.

Affected Version(s)

Backup and Recovery 15 <= 17.39

Disk Wiper 15 <= 16

Drive Copy 15 <= 16

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.