SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-36425

MEDIUM · CVSS 6.5 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The OPSWAT AppRemover Driver (ardrv.sys) prior to version 2017.10.02.1551 is vulnerable to unauthorized local users who can exploit the IOCTL handler 0x2420031 to send process termination requests without proper privilege validation. This flaw could lead to denial-of-service conditions or potential escalation of privileges for local attackers. Organizations using this driver should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-36425
Severity
MEDIUM
CVSS
6.5
EPSS
0.42%

Original NVD Description

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.