CVE-2026-36425
MEDIUMOPSWAT AppRemover Driver <= 2017.10.02.1551 - Unauthenticated Local Process Termination via IOCTL 0x2420031
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-36425. PoCs published by redteamfortress.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-36425, an improper access control vulnerability in OPSWAT AppRemover Driver (ardrv.sys) allowing unprivileged local users to terminate arbitrary processes via IOCTL 0x2420031 without privilege validation. The writeup includes root cause analysis, affected components, and impact assessment.
Description
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
Exploits (1)
Detailed technical analysis of CVE-2026-36425, an improper access control vulnerability in OPSWAT AppRemover Driver (ardrv.sys) allowing unprivileged local users to terminate arbitrary processes via IOCTL 0x2420031 without privilege validation. The writeup includes root cause analysis, affected components, and impact assessment.
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N