Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Security Update: Addressing the OPSWAT Legacy AppRemover Driver and CVE-2026-36425

By OPSWAT
Share this Post

Cybersecurity is an ongoing responsibility. Trust is built by developing secure products and by taking accountability when issues arise. At OPSWAT, an important part of that responsibility is actively pursuing transparency with our customers.

When a security issue involves our technology, we believe our customers deserve to hear directly from us clearly, honestly, and without unnecessary complexity.

We are aware of recent reports regarding CVE-2026-36425, a vulnerability in an older OPSWAT driver that was abused to interfere with security tools. This vulnerability was identified and addressed in June 2026, but we understand that seeing OPSWAT mentioned in connection with a security incident may raise concerns, which we want to address directly.

What was impacted and​ how OPSWAT fixed it

The issue affected the legacy ardrv.sys driver (v2017.10.02.1551 and earlier) used by AppRemover, our utility for cleanly uninstalling third-party applications. The driver was included as a component in products using the OESIS Framework, such as OPSWAT MetaDefender Endpoint, but had not shipped for several months.

The vulnerability could have allowed an unprivileged user to use the signed kernel driver to terminate protected processes, including security software. Attackers could have potentially abused this to disable security protections on an affected machine.

Once the vulnerability was published as CVE-2026-36425 on June 17, 2026, we took the following actions:

  • Deprecated the legacy ardrv.sys driver so that it is no longer included in, or supported by, OESIS Framework and MetaDefender Endpoint™
  • Replaced the legacy ardrv.sys driver with a new driver (libwasys.sys version 10.3.5429.0)
  • Thoroughly reviewed and tested the replacement to ensure that the new driver does not contain this security defect, because a newer driver is not automatically a safer one
  • Released the security fix on June 25, 2026 and notified impacted customers
  • Notified Microsoft team, which added the ardrv.sys driver to its block list effective September 1, 2026.

Given the sustained attention this vulnerability has received, we also notified MITRE to ensure the CVE record remains accurate and current. We are also continuing to review our processes and product components. Our goal is to learn from this individual issue to continually improve the security of our products.

What our customers need to do

To ensure your environment is protected, we strongly recommend upgrading to the latest version of your OPSWAT products.

  • Update the OESIS Framework to the June 25, 2026 release or later.
  • Update MetaDefender Endpoint to version 7.6.2606.1036 or later. You can download the latest version here.

If you are already running the latest version of OESIS Framework or MetaDefender Endpoint, no action is required. The latest version already replaced the affected driver and included security fixes.

Our commitment to transparency

We know that trust is earned through actions, not statements.

No software is immune to vulnerabilities, but we believe our responsibility goes beyond fixing issues.

After the vulnerability was identified, we addressed it in June 2026 by deprecating and replacing the legacy driver, and strengthened our testing processes as a result.

We will continue to pursue transparency, act responsibly when issues arise, and work every day to make our products more secure. Thank you for your continued trust in OPSWAT.

Tags:

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.