CVE-2025-0286

Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*

History

25 Jun 2025, 16:49

Type Values Removed Values Added
First Time Paragon-software paragon Hard Disk Manager
Paragon-software paragon Drive Copy
Paragon-software paragon Backup \& Recovery
Paragon-software paragon Migrate Os To Ssd
Paragon-software paragon Partition Manager
Paragon-software paragon Disk Wiper
Paragon-software
CWE CWE-1284
CPE cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*
References () https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys - () https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys - Vendor Advisory
References () https://www.kb.cert.org/vuls/id/726882 - () https://www.kb.cert.org/vuls/id/726882 - Third Party Advisory
References () https://www.paragon-software.com/support/#patches - () https://www.paragon-software.com/support/#patches - Product

14 Apr 2025, 21:15

Type Values Removed Values Added
Summary (en) Paragon Partition Manager version 17.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. (en) Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.

08 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-787

27 Mar 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Paragon Partition Manager versión 7.9.1 contiene una vulnerabilidad de escritura arbitraria en la memoria del kernel dentro de biontdrv.sys que es causada por una falla al validar correctamente la longitud de los datos proporcionados por el usuario, lo que puede permitir que un atacante ejecute código arbitrario en la máquina víctima.
Summary (en) Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. (en) Paragon Partition Manager version 17.9.1 contains an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
References
  • () https://www.paragon-software.com/support/#patches -

04 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

03 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 17:15

Updated : 2025-06-25 16:49


NVD link : CVE-2025-0286

Mitre link : CVE-2025-0286

CVE.ORG link : CVE-2025-0286


JSON object : View

Products Affected

paragon-software

  • paragon_drive_copy
  • paragon_hard_disk_manager
  • paragon_disk_wiper
  • paragon_partition_manager
  • paragon_backup_\&_recovery
  • paragon_migrate_os_to_ssd
CWE
CWE-1284

Improper Validation of Specified Quantity in Input