logo

Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks

ID: 04006d53-3068-5b0d-8cd6-6f3b8b50bc57

STIX ID: report--04006d53-3068-5b0d-8cd6-6f3b8b50bc57

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-03-01

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Microsoft disclosed five critical vulnerabilities in the Paragon Partition Manager kernel driver BioNTdrv.sys (multiple CVEs) and warned that one (CVE-2025-0289) is being actively exploited in Bring Your Own Vulnerable Driver (BYOVD) ransomware attacks to escalate to SYSTEM; Paragon has released patches and Microsoft added the driver to its Vulnerable Driver Blocklist, so users should update Paragon products and ensure the blocklist is enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.