OPSWAT AppRemover Product Security Update Advisory

OPSWAT AppRemover Product Security Update Advisory

Overview


It has been confirmed that a vulnerability in the OPSWAT AppRemover Driver (a driver is a component that operates between the operating system and hardware or software) has been exploited in actual attacks. The affected versions are OPSWAT AppRemover Driver (ardrv.Sys) v2017.10.02.1551 And earlier.

Vulnerability Information


This vulnerability, identified as CVE-2026-36425 with a CVSS score of 6.5, Allows an arbitrary process termination due to improper access control during the processing of IOCTL requests.

Impact and Response


Based on currently available information, no official security patches or updated versions have been released by the vendor. Therefore, organizations should check whether the vulnerable driver is installed and running; if the AppRemover feature is not in use, the driver should be uninstalled or disabled. Additionally, use security solutions to block the execution and loading of the vulnerable ardrv.Sys driver, and check OPSWAT’s official support channels through which patches or fixed versions are available.