CVE-2026-18605
Received Received - Intake

Uncontrolled Search Path in CheckMAL AppCheck Pro Kernel Mini-Filter Driver

Vulnerability report for CVE-2026-18605, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulDB

Description

A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
checkmal appcheck_pro 3.1.43.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a security flaw in CheckMAL AppCheck Pro 3.1.43.10 involving the AppCheckD.sys library in the Kernel Mini-Filter Driver component. It allows for uncontrolled search path manipulation through a local attack vector. The complexity is high, and exploitability is difficult, though a public exploit exists. The vendor did not respond to disclosure attempts.

Detection Guidance

Detection requires checking for the presence of AppCheckD.sys and analyzing its behavior. Inspect the system for the driver file in typical locations like C:\Windows\System32\drivers\. Use commands such as 'sc query AppCheckD' or 'driverquery /si' to list installed drivers. Monitor for unusual file access patterns or unauthorized modifications to system paths.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to manipulate system paths, potentially leading to unauthorized code execution or privilege escalation. This may result in data breaches, system compromise, or further network infiltration depending on the attacker's goals.

Compliance Impact

The vulnerability involves a local attack via a kernel mini-filter driver with uncontrolled search path, leading to potential privilege escalation or system compromise. This could result in unauthorized access to sensitive data, which may violate GDPR (data protection) and HIPAA (health data confidentiality) if exploited in systems handling such data.

Mitigation Strategies

Immediately remove or disable the AppCheckD.sys driver if present. Restrict local user permissions to prevent unauthorized driver installation. Update or patch the CheckMAL AppCheck Pro software if an update is available. Monitor network traffic for signs of exploitation attempts targeting this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18605. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart