60
CVE-2025-0289
—CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
Description
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
- Vendors
- paragon-software
- Products
- paragon backup \& recovery, paragon disk wiper, paragon drive copy, paragon hard disk manager, paragon migrate os to ssd, paragon partition manager
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H