← Volver a CVEs
CVE-2025-0286
HIGH8.4
Descripcion
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
Detalles CVE
Puntuacion CVSS v3.18.4
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/3/2025
Ultima modificacion6/25/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
paragon-software:paragon_backup_\&_recoveryparagon-software:paragon_disk_wiperparagon-software:paragon_drive_copyparagon-software:paragon_hard_disk_managerparagon-software:paragon_migrate_os_to_ssdparagon-software:paragon_partition_manager
Debilidades (CWE)
CWE-1284
Referencias
https://www.kb.cert.org/vuls/id/726882(cret@cert.org)
https://www.paragon-software.com/support/#patches(cret@cert.org)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.