CVE-2025-0288: Paragon-Software Paragon Backup & Recovery
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Affected products
- Paragon-Software Paragon Backup & Recovery: from 15, up to and including 17.39
- Paragon-Software Paragon Disk Wiper: from 15, up to and including 16
- Paragon-Software Paragon Drive Copy: from 15, up to and including 16
- Paragon-Software Paragon Hard Disk Manager: from 15, up to and including 17.39
- Paragon-Software Paragon Migrate OS To Ssd: from 4, up to and including 5
- Paragon-Software Paragon Partition Manager: from 15, up to and including 17.39
Published 2025-03-03. Last modified 2026-06-17.