{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/appcheck-pro-3.1.43.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-18605"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AppCheck Pro (3.1.43.10)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","kernel-driver"],"_cs_type":"advisory","_cs_vendors":["CheckMAL"],"content_html":"\u003cp\u003eA security vulnerability has been identified in CheckMAL AppCheck Pro version 3.1.43.10 involving an unknown function within the AppCheckD.sys kernel mini-filter driver. This flaw enables an attacker with local access to conduct an uncontrolled search path manipulation, potentially leading to unauthorized privilege escalation. While the vulnerability is reported as complex to exploit, a public exploit exists, increasing the risk for environments where this security software is deployed. CheckMAL has reportedly remained unresponsive to disclosure attempts, leaving the vulnerability unpatched in the specified version. Security teams should assess the presence of AppCheck Pro in their environment and monitor for local activities involving the driver.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to execute arbitrary code with kernel-level privileges. This facilitates a complete compromise of the affected host, enabling persistence, data exfiltration, and bypass of installed security controls. Given the nature of the software as a security product, its compromise undermines the integrity of the host's defensive posture.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all endpoints running CheckMAL AppCheck Pro 3.1.43.10 to identify exposure.\u003c/li\u003e\n\u003cli\u003eRestrict non-administrator local access to systems running this software to mitigate the local exploit vector.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual process execution or file modifications involving the AppCheckD.sys driver or associated application directories.\u003c/li\u003e\n\u003cli\u003eConsider alternative security solutions if the vendor continues to provide no patch for this critical-impact driver vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-03T18:05:54Z","date_published":"2026-08-03T18:05:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-checkmal-appcheck-privesc/","summary":"A local privilege escalation vulnerability in the AppCheckD.sys driver of CheckMAL AppCheck Pro version 3.1.43.10 allows attackers to perform uncontrolled search path manipulation.","title":"Local Privilege Escalation in CheckMAL AppCheck Pro via Kernel Driver","url":"https://feed.craftedsignal.io/briefs/2026-08-checkmal-appcheck-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - AppCheck Pro (3.1.43.10)","version":"https://jsonfeed.org/version/1.1"}