CVE-2026-36425 carries a CVSS 3.1 base score of 6.5 against OPSWAT’s AppRemover kernel driver, ardrv.sys, version 2017.10.02.1551 and earlier. NVD classifies it as CWE-269 (Improper Privilege Management). VulnCheck’s KEV feed reports the CVE as exploited, dated August 26, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-36425 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the driver exposes a device object that any local user can open, and one of its IOCTL handlers accepts process-termination requests without validating that the caller holds sufficient privilege to issue them. In effect, a low-privileged local process can direct the driver to terminate arbitrary other processes on the system — an operation that should require elevated privilege but does not.
Evidence and confidence
- Medium confidence — the CVSS 6.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), the CWE-269 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a public vulnerability-research repository cited in NVD’s own reference list. The exploitation report traces to VulnCheck KEV alone. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00422, a 35.9th percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field beyond NVD’s statement that version 2017.10.02.1551 and earlier are affected.
Why this matters
The CVSS vector requires local access and low privileges to exploit (AV:N here reflects the local device-object interface rather than network reachability, paired with PR:L), which narrows this to an escalation-after-initial-access scenario rather than a remote entry point. But a driver-level flaw that lets a low-privileged process kill arbitrary processes — including security tooling — is a meaningful post-compromise capability: it can be used to disable endpoint protection or monitoring agents running as separate processes on the same host, clearing the way for further malicious activity. Anti-malware and security-utility drivers are a recurring target for exactly this class of privilege-check gap, since they run with elevated access by design.
Frequently Asked Questions
What is CVE-2026-36425?
A CVSS 6.5 improper privilege management vulnerability (CWE-269) in OPSWAT’s AppRemover kernel driver (ardrv.sys), version 2017.10.02.1551 and earlier, that lets a local user terminate arbitrary processes without required privilege validation.
Is CVE-2026-36425 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 26, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? Yes. This requires existing local access and low-level privileges on the affected system — it is not remotely exploitable by an unauthenticated network attacker.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that version 2017.10.02.1551 and earlier are affected. Consult OPSWAT’s own product page for current driver availability.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-36425. Exploitation status and the August 26, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.