CVE Database
/

CVE-2025-0288

Back to search

CVE-2025-0288

Published: Mar 3, 2025

Modified: Sep 9, 2025

PUBLISHED

Description

Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.

VendorProductVersions

Paragon Software

Migrate OS to SSD

affected
4 - <= 5

Paragon Software

Disk Wiper

affected
15 - <= 16

Paragon Software

Drive Copy

affected
15 - <= 16

Paragon Software

Backup and Recovery

affected
15 - <= 17.39

Paragon Software

Hard Disk Manager

affected
15 - <= 17.39

Paragon Software

Partition Manager

affected
15 - <= 17.39

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now