Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-03-03 17:15
Updated : 2025-06-25 16:49
NVD link : CVE-2025-0288
Mitre link : CVE-2025-0288
CVE.ORG link : CVE-2025-0288
JSON object : View
Products Affected
paragon-software
- paragon_drive_copy
- paragon_disk_wiper
- paragon_migrate_os_to_ssd
- paragon_backup_\&_recovery
- paragon_partition_manager
- paragon_hard_disk_manager
CWE
