Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
ID: 04006d53-3068-5b0d-8cd6-6f3b8b50bc57
STIX ID: report--04006d53-3068-5b0d-8cd6-6f3b8b50bc57
Feed Name: Bleeping Computer
Threat Score
Microsoft disclosed five critical vulnerabilities in the Paragon Partition Manager kernel driver BioNTdrv.sys (multiple CVEs) and warned that one (CVE-2025-0289) is being actively exploited in Bring Your Own Vulnerable Driver (BYOVD) ransomware attacks to escalate to SYSTEM; Paragon has released patches and Microsoft added the driver to its Vulnerable Driver Blocklist, so users should update Paragon products and ensure the blocklist is enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
