PT-2025-9181 · Microsoft+1 · Windows+2

Published

2025-02-28

·

Updated

2026-04-14

·

CVE-2025-0289

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
Name of the Vulnerable Software and Affected Versions Paragon Partition Manager version 17 Paragon Partition Manager versions prior to 2.0.0
Description The issue is related to an insecure kernel resource access vulnerability in the BioNTdrv.sys driver, which can be exploited to compromise the service. This vulnerability is facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware. Attackers with local access can escalate privileges and run malicious code on Windows systems. The vulnerability has been exploited in ransomware attacks, specifically in BYOVD (Bring Your Own Vulnerable Driver) attacks, allowing attackers to gain SYSTEM privileges.
Recommendations For Paragon Partition Manager version 17, update to version 2.0.0 or later to resolve the issue. For Paragon Partition Manager versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the BioNTdrv.sys driver until a patch is available. Restrict access to the vulnerable driver to minimize the risk of exploitation. Avoid using the MappedSystemVa pointer in the affected API endpoint until the issue is resolved.

Fix

LPE

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-02229
CVE-2025-0289

Affected Products

Paragon Hard Disk Manager
Paragon Partition Manager
Windows