Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
History

Wed, 25 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Paragon-software
Paragon-software paragon Backup \& Recovery
Paragon-software paragon Disk Wiper
Paragon-software paragon Drive Copy
Paragon-software paragon Hard Disk Manager
Paragon-software paragon Migrate Os To Ssd
Paragon-software paragon Partition Manager
Weaknesses CWE-1284
CPEs cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*
Vendors & Products Paragon-software
Paragon-software paragon Backup \& Recovery
Paragon-software paragon Disk Wiper
Paragon-software paragon Drive Copy
Paragon-software paragon Hard Disk Manager
Paragon-software paragon Migrate Os To Ssd
Paragon-software paragon Partition Manager

Tue, 15 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 15 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Mon, 14 Apr 2025 20:30:00 +0000

Type Values Removed Values Added
Description Paragon Partition Manager version 17.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.

Tue, 08 Apr 2025 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 27 Mar 2025 19:00:00 +0000

Type Values Removed Values Added
Description Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. Paragon Partition Manager version 17.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
References

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
Description Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
Title CVE-2025-0286
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-03-03T16:25:25.767Z

Updated: 2025-04-15T15:16:27.115Z

Reserved: 2025-01-06T19:14:51.646Z

Link: CVE-2025-0286

cve-icon Vulnrichment

Updated: 2025-03-04T15:18:18.373Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T17:15:13.537

Modified: 2025-06-25T16:49:16.837

Link: CVE-2025-0286

cve-icon Redhat

No data.