CVE-2025-0289

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*

History

25 Jun 2025, 16:49

Type Values Removed Values Added
First Time Paragon-software paragon Partition Manager
Paragon-software paragon Migrate Os To Ssd
Paragon-software paragon Disk Wiper
Paragon-software paragon Drive Copy
Paragon-software
Paragon-software paragon Backup \& Recovery
Paragon-software paragon Hard Disk Manager
CPE cpe:2.3:a:paragon-software:paragon_hard_disk_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_partition_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_backup_\&_recovery:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_migrate_os_to_ssd:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_drive_copy:*:*:*:*:*:*:*:*
cpe:2.3:a:paragon-software:paragon_disk_wiper:*:*:*:*:*:*:*:*
References () https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys - () https://paragon-software.zendesk.com/hc/en-us/articles/32993902732817-IMPORTANT-Paragon-Driver-Security-Patch-for-All-Products-of-Hard-Disk-Manager-Product-Line-Biontdrv-sys - Vendor Advisory
References () https://www.kb.cert.org/vuls/id/726882 - () https://www.kb.cert.org/vuls/id/726882 - Third Party Advisory
References () https://www.paragon-software.com/support/#patches - () https://www.paragon-software.com/support/#patches - Product
CWE NVD-CWE-noinfo

14 Apr 2025, 21:15

Type Values Removed Values Added
Summary (en) Paragon Partition Manager version 17.9.1, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. (en) Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

27 Mar 2025, 20:15

Type Values Removed Values Added
Summary (en) Paragon Partition Manager version 17, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. (en) Paragon Partition Manager version 17.9.1, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

25 Mar 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

12 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown
CWE CWE-20

05 Mar 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) La versión 17 de Paragon Partition Manager, tanto la versión comunitaria como la empresarial, contienen una vulnerabilidad de acceso inseguro a los recursos del kernel facilitada por el controlador que no valida el puntero MappedSystemVa antes de pasarlo a HalReturnToFirmware, lo que puede permitir a un atacante comprometer el servicio.
References
  • () https://www.paragon-software.com/support/#patches -

04 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

03 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 17:15

Updated : 2025-06-25 16:49


NVD link : CVE-2025-0289

Mitre link : CVE-2025-0289

CVE.ORG link : CVE-2025-0289


JSON object : View

Products Affected

paragon-software

  • paragon_disk_wiper
  • paragon_migrate_os_to_ssd
  • paragon_partition_manager
  • paragon_drive_copy
  • paragon_hard_disk_manager
  • paragon_backup_\&_recovery