Privilege Escalation Issue in OPSWAT AppRemover Driver
CVE-2026-36425

6.5MEDIUM

Key Information:

Vendor

OPSWAT

Vendor
CVE Published:
16 July 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 1,930

What is CVE-2026-36425?

CVE-2026-36425 refers to a privilege escalation vulnerability found in OPSWAT's AppRemover Driver (ardrv.sys). This component is designed to facilitate the removal of applications and manage system resources effectively. The specific issue arises from flaws in an IOCTL handler that allows any local user to open the device and send process termination requests without the necessary privilege validation. Such a vulnerability poses a serious threat to organizations as it can enable malicious users to execute unauthorized commands, potentially leading to system destabilization or unauthorized access to sensitive data.

Potential impact of CVE-2026-36425

  1. Unauthorized System Control: Exploitation of this vulnerability could allow a local user to terminate critical processes without permissions, leading to unauthorized control over system operations and affecting overall system integrity.

  2. Increased Risk of Malware Deployment: By leveraging this privilege escalation, an attacker could manipulate system processes to deploy malware or other malicious software, compromising the security of the entire network.

  3. Data Breach Potential: With the ability to terminate processes, an attacker could disrupt security measures and gain access to sensitive information, ultimately leading to data breaches that affect the confidentiality, integrity, and availability of organizational data.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.