Impact
The flaw resides in an unknown function of the AppCheckD.sys kernel mini-filter driver bundled with CheckMAL AppCheck Pro. An attacker who can execute local code can manipulate the driver to trigger an uncontrolled search path, causing the system to load a malicious DLL instead of the legitimate one. The result is the potential execution of arbitrary code with kernel privileges, effectively elevating the attacker’s privileges on the compromised machine. The weakness is identified as CWE-426 and CWE-427.
Affected Systems
CheckMAL AppCheck Pro, version 3.1.43.10. Only this specific build is known to contain the vulnerable driver; other versions are not confirmed to be affected.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity for local exploitation. The EPSS score is not available, but the exploit has already been released to the public, raising the likelihood of real‑world attacks. The vulnerability is not listed in the CISA KEV catalog, yet the requirement for local access and the high complexity of the attack mean it is likely to be targeted only by attackers who already have some foothold within the system. The path-based nature of the flaw allows an adversary to override the trusted system paths used by the kernel loader, giving them a clear route to compromise the device.
OpenCVE Enrichment