OPSWAT AppRemover Driver Improper Access Control Vulnerability Allowing Process Termination

Vulnerability

A vulnerability exists in the OPSWAT AppRemover Driver (ardrv.sys) in versions through 2017.10.02.1551. The issue arises in the IOCTL handler 0x2420031, where the driver allows any local user to terminate processes without proper privilege validation. This flaw can be exploited to disrupt security software or critical system processes, leading to a denial-of-service condition and potential anti-forensic advantages.

Impact

Exploitation of this vulnerability allows unauthorized process termination, which can disable security software, cause system crashes, and disrupt logging or monitoring tools.

Remediation

Users should treat the AppRemover Driver (ardrv.sys) version 2017.10.02.1551 and earlier as vulnerable. If the AppRemover functionality is not needed, the driver should be removed or prevented from loading. For systems that require OPSWAT AppRemover, consider applying the latest updates or patches provided by OPSWAT.

Added: Jul 16, 2026, 11:18 PM
Updated: Jul 16, 2026, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
3.3
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.