Paragon Software develops a focused line of Windows-focused storage and system management utilities, including backup and recovery, disk-wiping, drive-copy, and OS-migration tools. This vendor profile represents a compact footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paragon Software over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0289HIGH Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to | Mar 3, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-0288HIGH Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize use | Mar 3, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-0286HIGH Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user sup | Mar 3, 2025 | 8.4 | 23 | NO | NO |
CVE-2025-0285HIGH Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user s | Mar 3, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-0287MEDIUM Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, | Mar 3, 2025 | 5.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paragon Software.
Media articles that mention a CVE ID that affects a product developed by Paragon Software — matched by CVE ID, not by vendor name.