Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory vulnerability facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
History

Wed, 05 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
References

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
Description Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory vulnerability facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
Title CVE-2025-0288
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-03-03T16:24:54.853Z

Updated: 2025-03-05T13:38:59.973Z

Reserved: 2025-01-06T19:15:19.554Z

Link: CVE-2025-0288

cve-icon Vulnrichment

Updated: 2025-03-04T15:20:17.348Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-03T17:15:13.823

Modified: 2025-03-05T14:15:36.390

Link: CVE-2025-0288

cve-icon Redhat

No data.