Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92253— Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine Restoration

Quick assessment

Affected
WatchDog Anti-Virus
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WatchDog Anti-Virus 1.8.640(Windows 版)在隔离文件恢复过程中存在“文件访问前链接解析不当”的漏洞。该漏洞允许本地低权限攻击者通过在原始文件路径处创建目录联接(directory junction),并诱使管理员恢复被隔离的文件,从而使被隔离的文件被写入任意文件系统位置。这可能导致受保护文件被篡改,或通过 DLL 劫持(DLL hijacking)实现 SYSTEM 级代码执行。

CVSS 5.2 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92253

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine Restoration
Source: CVE Program / CVE List V5
Vulnerability Description
Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a directory junction at the original file path and persuading an administrator to restore the file. This may enable modification of protected files or SYSTEM-level code execution through DLL hijacking.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/RE:L/U:Green
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WatchDog Anti-Virus 1.8.640 ~ 1.8.804 -

II. Public POCs for CVE-2026-92253

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92253

登录查看更多情报信息。

Vendor Pages for CVE-2026-92253 (1)

Same Patch Batch · WatchDog · 2026-09-20 · 3 CVEs total

CVE-2026-92254 6.9 MEDIUM WatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTL
CVE-2026-92252 5.9 MEDIUM Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory

IV. Related Vulnerabilities

V. Comments for CVE-2026-92253

No comments yet


Leave a comment