PT-2026-60576 · Undefined · Undefined

CVE-2026-36425

·

Published

2026-07-16

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OPSWAT AppRemover versions prior to 2017.10.02.1551
Description An issue exists in the IOCTL handler 0x2420031 of the OPSWAT AppRemover Driver (ardrv.sys). This flaw allows any local user to open the device and send process termination requests without proper privilege validation. In real-world incidents, a Cambodia-focused malware campaign has utilized a Bring Your Own Vulnerable Driver (BYOVD) technique to install this driver and abuse its kernel-level capabilities to terminate security software, including Microsoft Defender, Huorong Internet Security, 360 Total Security, and Tencent PC Manager, to facilitate the deployment of SparkRAT.
Recommendations Update OPSWAT AppRemover to a version later than 2017.10.02.1551. As a temporary mitigation, restrict the installation of unsigned or known vulnerable drivers to prevent BYOVD attacks.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36425

Affected Products

Undefined