CVE-2026-92253: Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine Restoration

Published Sep 20, 2026
·
Updated

Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a directory junction at the original file path and persuading an administrator to restore the file. This may enable modification of protected files or SYSTEM-level code execution through DLL hijacking.

Affected Software

1 affected component
Watchdog Anti-Virus=1.8.640

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WatchDog Anti-Virus to a version that resolves this vulnerability.

    Fixed in 1.8.640
  2. Compensating control

    Prevent untrusted/local low-privileged users from influencing quarantine restoration by restricting who can initiate/perform WatchDog Anti-Virus quarantine restoration (e.g., limit restore actions to trusted admin users and control access to the restore workflow on Windows).

Event History

Sep 20, 2026
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems running WatchDog Anti-Virus 1.8.640 on Windows are exposed when a local low-privileged user can create a directory junction at the quarantined file's original path and an administrator restores that file from quarantine.

2

What does an attacker need to exploit it?

The attacker needs local low-privileged access, the ability to create a directory junction at the original file path, and administrator action to restore the quarantined file. The issue is not described as remotely exploitable without local access or without an administrator performing the restoration.

3

What is the impact if exploitation succeeds?

A restored quarantined file can be written to an arbitrary filesystem location. This may allow modification of protected files or SYSTEM-level code execution through DLL hijacking.

4

What can be done if updating is not immediately possible?

Avoid restoring quarantined files whose original paths could have been replaced with directory junctions, and treat restore requests from untrusted local users as unsafe. Administrative review of the original restore path is necessary before restoring files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203