Vietnam.vn - Nền tảng quảng bá Việt Nam

Microsoft warns of security vulnerability in Windows disk management software

Báo Thanh niênBáo Thanh niên05/03/2025


According to BleepingComputer , Microsoft has added the BioNTdrv.sys driver to the block list due to the discovery of security vulnerabilities that can be exploited by hackers. The vulnerabilities were found in a kernel-level driver in the Paragon Partition Manager software. Hackers can exploit this driver to gain system-level control on Windows, thereby deploying ransomware attacks. If this software is already installed on the target device, attackers can take advantage of the existing vulnerability. Conversely, they can also install this driver to infiltrate the system in their own way.

According to CERT/CC, these vulnerabilities allow an attacker with local access to the device to escalate privileges or cause a denial of service (DoS) condition. In particular, because the BioNTdrv.sys driver is digitally signed by Microsoft, an attacker can use the "Bring Your Own Vulnerable Driver" (BYOVD) technique, which leverages legitimate but vulnerable drivers to exploit the system.

Microsoft said four of the five vulnerabilities affect Paragon Partition Manager versions 7.9.1 and earlier, while the fifth (CVE-2025-0298) affects versions 17 and earlier, which is also the vulnerability that has been actively exploited in recent ransomware attacks.

Cảnh báo lỗ hổng bảo mật trong phần mềm quản lý ổ đĩa trên Windows - Ảnh 1.

The Microsoft Vulnerable Driver Blocklist option being disabled leaves the device vulnerable to attacks via vulnerable drivers.

To mitigate the risk, Microsoft recommends that users upgrade to the latest version of the software, which includes the fixed BioNTdrv.sys 2.0.0. In addition to updating the software, users should also check and enable Microsoft's vulnerable driver blocklist by going to Settings > Privacy and Security > Windows Security > Device Security > Core Isolation > Microsoft Vulnerable Driver Blocklist and making sure it is enabled.



Source: https://thanhnien.vn/microsoft-canh-bao-lo-hong-bao-mat-cua-phan-mem-quan-ly-o-dia-tren-windows-185250304165924709.htm

Comment (0)

No data
No data

Same tag

Same category

People waited 5 hours to admire the brilliant fireworks in the sky of Ho Chi Minh City
Live: Opening of Thai Nguyen Tourism Season 2025
Close-up of traffic intersection in Quy Nhon that caused Binh Dinh to spend more than 500 billion on renovation
Chinese, Cambodian and Laotian armies hold joint military parade in Ho Chi Minh City

Same author

Heritage

Figure

Business

No videos available

News

Political System

Local

Product