CVE Database
/

CVE-2025-0289

Back to search

CVE-2025-0289

Published: Mar 3, 2025

Modified: Sep 9, 2025

PUBLISHED

Description

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

VendorProductVersions

Paragon Software

Migrate OS to SSD

affected
4 - <= 5

Paragon Software

Disk Wiper

affected
15 - <= 16

Paragon Software

Drive Copy

affected
15 - <= 16

Paragon Software

Hard Disk Manager

affected
15 - <= 17.39

Paragon Software

Backup and Recovery

affected
15 - <= 17.39

Paragon Software

Partition Manager

affected
15 - <= 17.39

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now