Null Pointer Dereference Vulnerability in Paragon Partition Manager by Paragon Software
CVE-2025-0287
5.1MEDIUM
Summary
Paragon Partition Manager version 7.9.1 is susceptible to a null pointer dereference vulnerability in the biontdrv.sys driver. This vulnerability is caused by an invalid MasterLrp structure in the input buffer, allowing attackers to exploit this flaw to execute arbitrary code within the kernel environment. Such an exploit can facilitate unauthorized privilege escalation, potentially compromising the integrity of the system.
Affected Version(s)
Backup and Recovery 15 <= 17.39
Disk Wiper 15 <= 16
Drive Copy 15 <= 16
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved