Filtered by vendor Opswat Subscriptions
Total 11 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-36425 1 Opswat 1 Appremover Driver 2026-08-12 6.5 Medium
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
CVE-2024-52925 1 Opswat 1 Metadefender Kiosk 2026-04-15 6.8 Medium
In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted USB drives.
CVE-2025-0131 1 Opswat 1 Metadefender Endpoint Security Sdk 2026-04-15 N/A
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtectâ„¢ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.
CVE-2024-57695 2 Agnitum, Opswat 2 Outpost Security Suite, Outpost Security Suite 2026-01-02 7.7 High
An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer fixed the vulnerability in version 8.0 (4164.652.1856) from December 17, 2012.
CVE-2023-36659 1 Opswat 1 Metadefender Kiosk 2024-11-21 9.8 Critical
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).
CVE-2023-36658 1 Opswat 2 Media Validation Agent, Metadefender Kiosk 2024-11-21 7.8 High
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.
CVE-2023-36657 1 Opswat 1 Metadefender Kiosk 2024-11-21 9.8 Critical
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.
CVE-2022-40778 1 Opswat 1 Metadefender 2024-11-21 5.4 Medium
A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked page response.
CVE-2022-32273 1 Opswat 1 Metadefender 2024-11-21 4.3 Medium
As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.
CVE-2022-32272 1 Opswat 1 Metadefender 2024-11-21 9.8 Critical
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
CVE-2018-16275 1 Opswat 1 Metadefender 2024-11-21 N/A
OPSWAT MetaDefender before v4.11.2 allows CSV injection.