CyberRota Analysis
AI-GeneratedThe OPSWAT AppRemover Driver (ardrv.sys) prior to version 2017.10.02.1551 is vulnerable to unauthorized local users who can exploit the IOCTL handler 0x2420031 to send process termination requests without proper privilege validation. This flaw could lead to denial-of-service conditions or potential escalation of privileges for local attackers. Organizations using this driver should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.