CVE-2025-0288
63Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 7.8epss 0.5%
from disclosure to weapon75 days
Published on NVDMar 3
1st PoC+75d
VulnCheck+94d
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Paragon Software · Backup and RecoveryParagon Software · Disk WiperParagon Software · Drive CopyParagon Software · Hard Disk ManagerParagon Software · Migrate OS to SSDParagon Software · Partition Managerpublic PoCs found — 2
vulncheckvulncheck.com/xdb/583b7e9ee41eunverifiedvulncheckvulncheck.com/xdb/8071c3dc955cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.