CVE-2026-92252: Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory

Published Sep 20, 2026
·
Updated

Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus. This may disable antivirus protection or enable privileged code execution if modified binaries are loaded by an elevated WatchDog process.

Affected Software

1 affected component
Watchdog Anti-Virus

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update NTFS permissions on the WatchDog Anti-Virus installation directory (C:\Program Files (x86)\Watchdog Anti-Virus) so the Users group no longer has Full Control; restrict write/modify/delete rights to administrators/system to prevent low-privileged users from replacing or deleting antivirus binaries/configuration files.

    WatchDog Anti-Virus on Windows NTFS permissions on C:\Program Files (x86)\Watchdog Anti-Virus (remove Users group Full Control) = Users group Full Control -> no write permissions (restrict to Administrators/system)

Event History

Sep 20, 2026
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A local user with low privileges on Windows can exploit it if WatchDog Anti-Virus is installed with the affected default directory permissions. The user does not need administrative rights to modify files in the installation directory.

2

What must an attacker do to achieve privileged code execution?

The attacker must modify or replace a WatchDog binary that is subsequently loaded by an elevated WatchDog process. They may also delete or alter antivirus files to disable protection.

3

Are default installations affected?

Yes. The issue is caused by the installer granting the Windows Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus.

4

How can I check whether a system is affected?

Inspect the access permissions on C:\Program Files (x86)\Watchdog Anti-Virus. A system is affected if the Users group has Full Control, allowing non-administrative users to modify, replace, or delete files there.

5

What can be done before a vendor fix is available?

Remove Full Control permissions for the Users group from the WatchDog Anti-Virus installation directory and ensure that low-privileged accounts cannot modify its binaries or configuration files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203