CVE-2025-0287: Paragon-Software Paragon Backup & Recovery

Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

Affected products

Published 2025-03-03. Last modified 2026-06-17.