WatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated IOCTL
Summary
| CVE | CVE-2026-92254 |
|---|---|
| State | PUBLISHED |
| Assigner | watchdog |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-20 13:17:46 UTC |
| Updated | 2026-09-20 13:17:46 UTC |
| Description | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling security products or destabilizing the operating system, via crafted IOCTL requests sent to the \Device\wsdk device. |
Risk And Classification
Primary CVSS: v4.0 6.9 MEDIUM from 34edf4f2-2577-40ab-82ce-39f45972c129
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:Amber
Problem Types: CWE-20 | CWE-306 | CWE-20 CWE-20 Improper input validation | CWE-306 CWE-306 Missing authentication for critical function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 34edf4f2-2577-40ab-82ce-39f45972c129 | Secondary | 6.9 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.9 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/... |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:Amber
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Watchdog | Anti-Virus | affected 1.8.640 1.8.804 semver | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| watchdog.com/vulnerability-disclosure-policy | 34edf4f2-2577-40ab-82ce-39f45972c129 | watchdog.com | |
| watchdog.com/anti-virus-release-notes | 34edf4f2-2577-40ab-82ce-39f45972c129 | watchdog.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Patrick Tung (en)
There are currently no legacy QID mappings associated with this CVE.