Executive brief
Watchdog WatchDog Antivirus contains a missing authorization flaw in its kernel driver that allows low-privileged local users to delete arbitrary files with SYSTEM privileges. An attacker can exploit this to bypass Windows file protections, delete critical security software, or destabilize the operating system by sending specially crafted requests to the driver.
Technical details
The wsdkd.sys kernel driver fails to properly validate authorization in its IOCTL handlers, allowing any local user to send crafted IOCTL requests to the \Device\wsdk device and perform privileged file deletion operations. The vulnerability requires local code execution but no special privileges; the attacker gains the ability to delete files with SYSTEM-level permissions, bypassing NTFS access controls. A fix is available in driver version 2.3.2.0 (released 2025-07-02) and later.
Affected products
- Watchdog WatchDog Antivirus 1.8.640 and earlier with driver version 1.3.0.0 and earlier
Timeline
- 2026-09-20: disclosed
- 2025-07-02: patched: Fixed in WSDK driver version 2.3.2.0 released in WatchDog Antivirus 1.8.606