CVE-2026-36425 Details
Description
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
A vulnerability exists in the OPSWAT AppRemover Driver (ardrv.sys) in versions through 2017.10.02.1551. The issue arises in the IOCTL handler 0x2420031, where the driver allows any local user to terminate processes without proper privilege validation. This flaw can be exploited to disrupt security software or critical system processes, leading to a denial-of-service condition and potential anti-forensic advantages.
Users should treat the AppRemover Driver (ardrv.sys) version 2017.10.02.1551 and earlier as vulnerable. If the AppRemover functionality is not needed, the driver should be removed or prevented from loading. For systems that require OPSWAT AppRemover, consider applying the latest updates or patches provided by OPSWAT.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | [email protected] |