Impact
The OPSWAT AppRemover Driver (ardrv.sys) contains a flaw in its IOCTL handler 0x2420031. The flaw bypasses privilege validation, allowing any local user who can open the driver device to request the termination of arbitrary processes. This means an attacker with a user account on the system could cause a denial of service by aborting critical or privileged processes without requiring elevated privileges.
Affected Systems
The vulnerability affects installations of the OPSWAT AppRemover framework that include the ardrv.sys driver with a version earlier than v2017.10.02.1551. These driver files are typically deployed on systems running the OPSWAT AppRemover product, most commonly in Windows environments where ardrv.sys is a kernel‑mode driver.
Risk and Exploitability
Exploitation requires local access; an attacker must have a user account that can open the device. The EPSS score is below 1 %, indicating a low likelihood of real‑world exploitation as of the current data. The vulnerability is not listed in the CISA KEV catalog, and no publicly known exploits have been reported. Nonetheless, the lack of privilege checks means any local user could interrupt critical system functions, resulting in a denial of service.
OpenCVE Enrichment