Description
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
Published: 2026-07-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The OPSWAT AppRemover Driver (ardrv.sys) contains a flaw in its IOCTL handler 0x2420031. The flaw bypasses privilege validation, allowing any local user who can open the driver device to request the termination of arbitrary processes. This means an attacker with a user account on the system could cause a denial of service by aborting critical or privileged processes without requiring elevated privileges.

Affected Systems

The vulnerability affects installations of the OPSWAT AppRemover framework that include the ardrv.sys driver with a version earlier than v2017.10.02.1551. These driver files are typically deployed on systems running the OPSWAT AppRemover product, most commonly in Windows environments where ardrv.sys is a kernel‑mode driver.

Risk and Exploitability

Exploitation requires local access; an attacker must have a user account that can open the device. The EPSS score is below 1 %, indicating a low likelihood of real‑world exploitation as of the current data. The vulnerability is not listed in the CISA KEV catalog, and no publicly known exploits have been reported. Nonetheless, the lack of privilege checks means any local user could interrupt critical system functions, resulting in a denial of service.

Generated by OpenCVE AI on August 5, 2026 at 02:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a recent OPSWAT AppRemover Driver release that includes the IOCTL privilege check fix
  • If an update is not possible, uninstall or disable the ardrv.sys driver to remove the vulnerable interface
  • Configure device access controls or local security policy to restrict opening of ardrv.sys to administrators only

Generated by OpenCVE AI on August 5, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local User Process Termination via Unprivileged IOCTL in OPSWAT AppRemover Driver
Weaknesses CWE-284
CWE-732

Tue, 04 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unprivileged Process Termination via OPSWAT AppRemover Driver
Weaknesses CWE-285

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Opswat
Opswat appremover Driver
Vendors & Products Opswat
Opswat appremover Driver

Sun, 26 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unprivileged Process Termination via OPSWAT AppRemover Driver
Weaknesses CWE-285

Sat, 25 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Privilege-Invalid Process Termination via OPSWAT AppRemover Driver
Weaknesses CWE-285

Wed, 22 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege-Invalid Process Termination via OPSWAT AppRemover Driver
Weaknesses CWE-285

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
References

Subscriptions

Opswat Appremover Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T13:32:35.354Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36425

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource