<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>AppCheck Pro (3.1.43.10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/appcheck-pro-3.1.43.10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 18:05:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/appcheck-pro-3.1.43.10/feed.xml" rel="self" type="application/rss+xml"/><item><title>Local Privilege Escalation in CheckMAL AppCheck Pro via Kernel Driver</title><link>https://feed.craftedsignal.io/briefs/2026-08-checkmal-appcheck-privesc/</link><pubDate>Mon, 03 Aug 2026 18:05:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-checkmal-appcheck-privesc/</guid><description>A local privilege escalation vulnerability in the AppCheckD.sys driver of CheckMAL AppCheck Pro version 3.1.43.10 allows attackers to perform uncontrolled search path manipulation.</description><content:encoded><![CDATA[<p>A security vulnerability has been identified in CheckMAL AppCheck Pro version 3.1.43.10 involving an unknown function within the AppCheckD.sys kernel mini-filter driver. This flaw enables an attacker with local access to conduct an uncontrolled search path manipulation, potentially leading to unauthorized privilege escalation. While the vulnerability is reported as complex to exploit, a public exploit exists, increasing the risk for environments where this security software is deployed. CheckMAL has reportedly remained unresponsive to disclosure attempts, leaving the vulnerability unpatched in the specified version. Security teams should assess the presence of AppCheck Pro in their environment and monitor for local activities involving the driver.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local attacker to execute arbitrary code with kernel-level privileges. This facilitates a complete compromise of the affected host, enabling persistence, data exfiltration, and bypass of installed security controls. Given the nature of the software as a security product, its compromise undermines the integrity of the host's defensive posture.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all endpoints running CheckMAL AppCheck Pro 3.1.43.10 to identify exposure.</li>
<li>Restrict non-administrator local access to systems running this software to mitigate the local exploit vector.</li>
<li>Monitor for unusual process execution or file modifications involving the AppCheckD.sys driver or associated application directories.</li>
<li>Consider alternative security solutions if the vendor continues to provide no patch for this critical-impact driver vulnerability.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>windows</category><category>kernel-driver</category></item></channel></rss>