CVE-2026-92253: Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine Restoration
Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a directory junction at the original file path and persuading an administrator to restore the file. This may enable modification of protected files or SYSTEM-level code execution through DLL hijacking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchDog Anti-Virusto a version that resolves this vulnerability.Fixed in 1.8.640 - Compensating control
Prevent untrusted/local low-privileged users from influencing quarantine restoration by restricting who can initiate/perform WatchDog Anti-Virus quarantine restoration (e.g., limit restore actions to trusted admin users and control access to the restore workflow on Windows).
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running WatchDog Anti-Virus 1.8.640 on Windows are exposed when a local low-privileged user can create a directory junction at the quarantined file's original path and an administrator restores that file from quarantine.
What does an attacker need to exploit it?
The attacker needs local low-privileged access, the ability to create a directory junction at the original file path, and administrator action to restore the quarantined file. The issue is not described as remotely exploitable without local access or without an administrator performing the restoration.
What is the impact if exploitation succeeds?
A restored quarantined file can be written to an arbitrary filesystem location. This may allow modification of protected files or SYSTEM-level code execution through DLL hijacking.
What can be done if updating is not immediately possible?
Avoid restoring quarantined files whose original paths could have been replaced with directory junctions, and treat restore requests from untrusted local users as unsafe. Administrative review of the original restore path is necessary before restoring files.