← back
CVE-2025-0289highobserved exploitation

CVE-2025-0289

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.8epss 0.3%
from disclosure to weapon
Published on NVDMar 3
VulnCheckFeb 28
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
yesVulnCheck
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H