Medium severity5.1NVD Advisory· Published Mar 3, 2025· Updated Jun 17, 2026
CVE-2025-0287
CVE-2025-0287
Description
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*Range: >=15,<=17.39
- cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*Range: >=15,<=16
- cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*Range: >=15,<=16
- cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*Range: >=15,<=17.39
- cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*Range: >=4,<=5
- cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*Range: >=15,<=17.39
- Range: 15
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.