Microsoft discovers five potentially damaging attacks against its own software


- Microsoft patches Paragon Partition Manager, after finding five flaws in a kernel-level driver
- One of the flaws was being actively used to drop ransomware
- The driver can be abused even without the partition manager installed
Hackers are using a vulnerable Windows driver to escalate privileges through Microsoft software, allowing possible ransomware attacks via zero-days.
Microsoft confirmed the findings when it added the affected version of the driver to its Vulnerable Driver Blocklist – and at the same time, it patched five flaws in the flawed software and urged users to apply updates as soon as possible.
The flaws were apparently found in BioNTdrv.sys, a kernel-level driver for a piece of software called Paragon Partition Manager. Cybercriminals who already managed to gain some access to a target endpoint would either use this driver (if the software is installed on the device), or drop it, to gain SYSTEM privileges in Windows, used to mount ransomware attacks.
Checking the blocklist
“An attacker with local access to a device can exploit these vulnerabilities to escalate privileges or cause a denial-of-service (DoS) scenario on the victim’s machine,” CERT/CC said. “Additionally, as the attack involves a Microsoft-signed Driver, an attacker can leverage a Bring Your Own Vulnerable Driver (BYOVD) technique to exploit systems even if Paragon Partition Manager is not installed. “
Microsoft said four of the flaws affected Paragon Partition Manager versions 7.9.1 and older, with the fifth one (CVE-2025-0298) impacting version 17 and older – which was also the one apparently being actively exploited in ransomware attacks.
Now, users are urged to upgrade the software to the latest version, since it also comes with BioNTdrv.sys version 2.0.0.
Besides upgrading the software, users should also double-check if the blocklist is enabled, by going to Settings – Privacy and Security – Windows Security – Device Security – Core Isolation – Microsoft Vulnerable Driver Blocklist and making sure it’s turned on.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
You might also like
Microsoft patches Paragon Partition Manager, after finding five flaws in a kernel-level driver One of the flaws was being actively used to drop ransomware The driver can be abused even without the partition manager installed Hackers are using a vulnerable Windows driver to escalate privileges through Microsoft software, allowing possible…
Recent Posts
- Microsoft discovers five potentially damaging attacks against its own software
- US government cuts key software division without warning
- Tonal 2 Review: Smarter Strength Training
- Blue Ghost private lander reaches the Moon intact
- The Samsung Galaxy S26 Ultra could have even smaller bezels – and that could mean an even bigger display
Archives
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010