← back
CVE-2025-0287mediumobserved exploitationCWE-476

CVE-2025-0287

35Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 5.1epss 0.4%
from disclosure to weapon
Published on NVDMar 3
VulnCheck+94d
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
yesVulnCheck
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N