PT-2026-60576 · Undefined · Undefined
CVE-2026-36425
·
Published
2026-07-16
·
Updated
2026-08-28
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OPSWAT AppRemover versions prior to 2017.10.02.1551
Description
An issue exists in the IOCTL handler 0x2420031 of the OPSWAT AppRemover Driver (
ardrv.sys). This flaw allows any local user to open the device and send process termination requests without proper privilege validation. In real-world incidents, a Cambodia-focused malware campaign has utilized a Bring Your Own Vulnerable Driver (BYOVD) technique to install this driver and abuse its kernel-level capabilities to terminate security software, including Microsoft Defender, Huorong Internet Security, 360 Total Security, and Tencent PC Manager, to facilitate the deployment of SparkRAT.Recommendations
Update OPSWAT AppRemover to a version later than 2017.10.02.1551.
As a temporary mitigation, restrict the installation of unsigned or known vulnerable drivers to prevent BYOVD attacks.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined