CVE-2025-0289
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 15 to 17.39 | |
| From 15 to 16 | |
| From 15 to 16 | |
| From 15 to 17.39 | |
| From 4 to 5 | |
| From 15 to 17.39 |
References (3)
Source: cret@cert.org
Vendor Advisory
Timeline
No history available yet.