CVE-2025-0286: Paragon-Software Paragon Backup & Recovery
High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
Affected products
- Paragon-Software Paragon Backup & Recovery: from 15, up to and including 17.39
- Paragon-Software Paragon Disk Wiper: from 15, up to and including 16
- Paragon-Software Paragon Drive Copy: from 15, up to and including 16
- Paragon-Software Paragon Hard Disk Manager: from 15, up to and including 17.39
- Paragon-Software Paragon Migrate OS To Ssd: from 4, up to and including 5
- Paragon-Software Paragon Partition Manager: from 15, up to and including 17.39
Published 2025-03-03. Last modified 2026-06-17.