PT-2025-9181 · Microsoft+1 · Windows+2
Published
2025-02-28
·
Updated
2026-04-14
·
CVE-2025-0289
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber |
Name of the Vulnerable Software and Affected Versions
Paragon Partition Manager version 17
Paragon Partition Manager versions prior to 2.0.0
Description
The issue is related to an insecure kernel resource access vulnerability in the BioNTdrv.sys driver, which can be exploited to compromise the service. This vulnerability is facilitated by the driver not validating the
MappedSystemVa pointer before passing it to HalReturnToFirmware. Attackers with local access can escalate privileges and run malicious code on Windows systems. The vulnerability has been exploited in ransomware attacks, specifically in BYOVD (Bring Your Own Vulnerable Driver) attacks, allowing attackers to gain SYSTEM privileges.Recommendations
For Paragon Partition Manager version 17, update to version 2.0.0 or later to resolve the issue.
For Paragon Partition Manager versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue.
As a temporary workaround, consider disabling the
BioNTdrv.sys driver until a patch is available.
Restrict access to the vulnerable driver to minimize the risk of exploitation.
Avoid using the MappedSystemVa pointer in the affected API endpoint until the issue is resolved.Fix
LPE
Improper Access Control
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Paragon Hard Disk Manager
Paragon Partition Manager
Windows