Junglewise Threat Intelligence

CVE-2026-92253: WatchDog Anti-Virus directory junction symlink attack in quarantine restoration

CVE-2026-92253 · Severity: info · Published 2026-09-20

Executive brief

WatchDog Anti-Virus is security software that protects Windows systems from malware threats. The quarantine restoration feature fails to properly validate file paths before restoring quarantined files, allowing a local attacker to create a directory junction that redirects file restoration to arbitrary locations on disk. An attacker can exploit this by tricking an administrator into restoring a quarantined file, resulting in arbitrary files being written to protected system directories or enabling DLL hijacking attacks that lead to complete system compromise.

Technical details

The vulnerability is a directory junction (symlink) attack in the quarantine restoration process that fails to properly resolve symbolic links before file access (CWE-59: Improper Link Resolution Before File Access). An unauthenticated local, low-privileged attacker can create a directory junction at a quarantined file's original path and persuade an administrator to restore the file, causing it to be written to an attacker-chosen location. This enables DLL hijacking or overwriting protected system files, resulting in SYSTEM-level code execution.

Affected products

  • WatchDog Anti-Virus 1.8.640

Timeline

  • 2026-09-20: disclosed

References

Related threats