CVE-2026-36425: Medium severity OPSWAT OPSWAT AppRemover Driver vulnerability
Published Jul 16, 2026
·Updated
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
Affected Software
1 affected component
OPSWAT OPSWAT AppRemover Driver<=2017.10.02.1551
Event History
Jul 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36425?
The severity of CVE-2026-36425 is medium with a CVSS score of 6.5.
2
How do I fix CVE-2026-36425?
To fix CVE-2026-36425, update the OPSWAT AppRemover Driver to version 2017.10.02.1552 or later.
3
What is the impact of CVE-2026-36425?
CVE-2026-36425 allows any local user to terminate processes without proper privilege validation.
4
Who is affected by CVE-2026-36425?
CVE-2026-36425 affects systems running OPSWAT AppRemover Driver version 2017.10.02.1551 and earlier.
5
What should I do if I cannot update OPSWAT AppRemover Driver for CVE-2026-36425?
If unable to update, consider restricting access to the device driver or implementing other security measures to mitigate the risk.