#VU105166 Improper access control in BioNTdrv.sys and Partition Manager - CVE-2025-0289
Published: February 28, 2025 / Updated: March 3, 2025
BioNTdrv.sys
Partition Manager
Paragon Technologie GmbH
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions when validating the MappedSystemVa pointer before passing it to HalReturnToFirmware. A local user can execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.