CVE-2025-0287: Paragon-Software Paragon Backup & Recovery
Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
Affected products
- Paragon-Software Paragon Backup & Recovery: from 15, up to and including 17.39
- Paragon-Software Paragon Disk Wiper: from 15, up to and including 16
- Paragon-Software Paragon Drive Copy: from 15, up to and including 16
- Paragon-Software Paragon Hard Disk Manager: from 15, up to and including 17.39
- Paragon-Software Paragon Migrate OS To Ssd: from 4, up to and including 5
- Paragon-Software Paragon Partition Manager: from 15, up to and including 17.39
Published 2025-03-03. Last modified 2026-06-17.