CVE-2025-0289: Paragon-Software Paragon Backup & Recovery
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Affected products
- Paragon-Software Paragon Backup & Recovery: from 15, up to and including 17.39
- Paragon-Software Paragon Disk Wiper: from 15, up to and including 16
- Paragon-Software Paragon Drive Copy: from 15, up to and including 16
- Paragon-Software Paragon Hard Disk Manager: from 15, up to and including 17.39
- Paragon-Software Paragon Migrate OS To Ssd: from 4, up to and including 5
- Paragon-Software Paragon Partition Manager: from 15, up to and including 17.39
Published 2025-03-03. Last modified 2026-06-17.