CVE-2026-92252: Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory
Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus. This may disable antivirus protection or enable privileged code execution if modified binaries are loaded by an elevated WatchDog process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update NTFS permissions on the WatchDog Anti-Virus installation directory (C:\Program Files (x86)\Watchdog Anti-Virus) so the Users group no longer has Full Control; restrict write/modify/delete rights to administrators/system to prevent low-privileged users from replacing or deleting antivirus binaries/configuration files.
WatchDog Anti-Virus on Windows NTFS permissions on C:\Program Files (x86)\Watchdog Anti-Virus (remove Users group Full Control) = Users group Full Control -> no write permissions (restrict to Administrators/system)
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user with low privileges on Windows can exploit it if WatchDog Anti-Virus is installed with the affected default directory permissions. The user does not need administrative rights to modify files in the installation directory.
What must an attacker do to achieve privileged code execution?
The attacker must modify or replace a WatchDog binary that is subsequently loaded by an elevated WatchDog process. They may also delete or alter antivirus files to disable protection.
Are default installations affected?
Yes. The issue is caused by the installer granting the Windows Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus.
How can I check whether a system is affected?
Inspect the access permissions on C:\Program Files (x86)\Watchdog Anti-Virus. A system is affected if the Users group has Full Control, allowing non-administrative users to modify, replace, or delete files there.
What can be done before a vendor fix is available?
Remove Full Control permissions for the Users group from the WatchDog Anti-Virus installation directory and ensure that low-privileged accounts cannot modify its binaries or configuration files.