CVE-2025-0287

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
Configurations

No configuration.

History

14 Apr 2025, 21:15

Type Values Removed Values Added
Summary (en) Paragon Partition Manager version 17.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation. (en) Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

27 Mar 2025, 19:15

Type Values Removed Values Added
Summary (en) Paragon Partition Manager version 7.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation. (en) Paragon Partition Manager version 17.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

05 Mar 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.paragon-software.com/support/#patches -
Summary
  • (es) Paragon Partition Manager versión 7.9.1 contiene una vulnerabilidad de desreferencia de puntero nulo dentro de biontdrv.sys que es causada por la falta de una estructura MasterLrp válida en el búfer de entrada, lo que permite a un atacante ejecutar código arbitrario en el kernel, facilitando la escalada de privilegios.

03 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1
CWE CWE-476

03 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 17:15

Updated : 2025-04-14 21:15


NVD link : CVE-2025-0287

Mitre link : CVE-2025-0287

CVE.ORG link : CVE-2025-0287


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference