Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Prioritize remediation for paragon-software paragon_backup_\&_recovery systems immediately
Assume compromise if assets are exposed
Track advisory updates for patch or workaround availability
Recommended action window: Immediate (within 24h)
NVD description
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
🚨 [HIGH] Active exploitation detected: CVE-2025-0287
Exploit in the wild confirmed for CVE-2025-0287 (CVSS null). Various Paragon Software products contain a null pointer dereference vulnerability within...
🔗 http://ctiwatch.cloud/alerts
#ZeroDay#ExploitInWild#CyberSecurity
Post summary
The alert confirms CVE‑2025‑0287 is actively exploited in the wild, citing a null‑pointer dereference in Paragon products, but no PoC, patch, or false‑positive information is included.