CVE-2025-0285: Paragon-Software Paragon Backup & Recovery

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

Affected products

Published 2025-03-03. Last modified 2026-06-17.