Executive brief
WatchDog Anti-Virus is security software that protects Windows systems from malware threats. The quarantine restoration feature fails to properly validate file paths before restoring quarantined files, allowing a local attacker to create a directory junction that redirects file restoration to arbitrary locations on disk. An attacker can exploit this by tricking an administrator into restoring a quarantined file, resulting in arbitrary files being written to protected system directories or enabling DLL hijacking attacks that lead to complete system compromise.
Technical details
The vulnerability is a directory junction (symlink) attack in the quarantine restoration process that fails to properly resolve symbolic links before file access (CWE-59: Improper Link Resolution Before File Access). An unauthenticated local, low-privileged attacker can create a directory junction at a quarantined file's original path and persuade an administrator to restore the file, causing it to be written to an attacker-chosen location. This enables DLL hijacking or overwriting protected system files, resulting in SYSTEM-level code execution.
Affected products
- WatchDog Anti-Virus 1.8.640
Timeline
- 2026-09-20: disclosed