Improper access control in BioNTdrv.sys and Partition Manager - CVE-2025-0289
Published: February 28, 2025 / Updated: March 3, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions when validating the MappedSystemVa pointer before passing it to HalReturnToFirmware. A local user can execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Partition Manager
SupportAssist OS Recovery
How to mitigate CVE-2025-0289
Partition Manager - update to 17.45.0
SupportAssist OS Recovery - update to 5.5.13.2