CVE-2025-0287Active Exploitation(paragon-software / paragon_backup_\&_recovery)

MEDIUMCVSS 5.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for paragon-software paragon_backup_\&_recovery systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • paragon_backup_\&_recovery
  • paragon_disk_wiper
  • paragon_drive_copy
  • paragon_hard_disk_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
paragon_backup_\&_recoveryparagon_disk_wiperparagon_drive_copyparagon_hard_disk_managerparagon_migrate_os_to_ssdparagon_partition_manager

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-06-28: 1Active Exploitation · 2026-04-14: 1Technical Details · 2026-04-14: 104-1406-28
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-141
Active Exploitation1
2026-06-281
Disclosure1
Full discourse2 posts
  • Meisam Ebrahimi@meysam_Mr_Fox
    Disclosure

    Published a root cause analysis of CVE-2025-0288 in BioNTDrv.sys. https://meisameb.github.io/posts/cve-2025-0287/

    Post summary

    A root‑cause analysis of CVE‑2025‑0288 in BioNTDrv.sys was published, but the brief text gives no PoC, exploit, or patch details.

    0001045
    12 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-0287 Exploit in the wild confirmed for CVE-2025-0287 (CVSS null). Various Paragon Software products contain a null pointer dereference vulnerability within... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The alert confirms CVE‑2025‑0287 is actively exploited in the wild, citing a null‑pointer dereference in Paragon products, but no PoC, patch, or false‑positive information is included.

    00000235
    5.6K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appparagon-softwareparagon_backup_\&_recovery---
Appparagon-softwareparagon_disk_wiper---
Appparagon-softwareparagon_drive_copy---
Appparagon-softwareparagon_hard_disk_manager---
Appparagon-softwareparagon_migrate_os_to_ssd---
Appparagon-softwareparagon_partition_manager---

Explore more