CVE-2026-92253: CWE-59 Improper link resolution before file access ('link following') in WatchDog Anti-Virus
CVE-2026-92253 is a medium severity vulnerability in WatchDog Anti-Virus 1.8.640 through 1.8.803 on Windows. It involves improper link resolution during the quarantine restoration process, allowing a local low-privileged attacker to create a directory junction at the original file path. If an administrator restores the quarantined file, this can cause the file to be written to an arbitrary location, potentially enabling modification of protected files or SYSTEM-level code execution via DLL hijacking.
AI Analysis
Technical Summary
This vulnerability arises from improper handling of symbolic links (directory junctions) before file access in the quarantine restoration feature of WatchDog Anti-Virus versions >=1.8.640 and <1.8.804 on Windows. A local attacker with low privileges can exploit this by creating a directory junction at the path of a quarantined file and then convincing an administrator to restore that file. The restoration process follows the link, causing the file to be written to an unintended location. This can lead to modification of protected system files or execution of code with SYSTEM privileges through DLL hijacking techniques.
Potential Impact
The vulnerability allows local low-privileged attackers to influence the location where quarantined files are restored by exploiting improper link resolution. This can result in unauthorized modification of protected files or enable SYSTEM-level code execution via DLL hijacking, potentially compromising system integrity and security.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. Users should check the vendor advisory for updates. Until a fix is available, administrators should exercise caution when restoring quarantined files, especially verifying the file paths and ensuring no suspicious directory junctions exist at those locations.
CVE-2026-92253: CWE-59 Improper link resolution before file access ('link following') in WatchDog Anti-Virus
Description
CVE-2026-92253 is a medium severity vulnerability in WatchDog Anti-Virus 1.8.640 through 1.8.803 on Windows. It involves improper link resolution during the quarantine restoration process, allowing a local low-privileged attacker to create a directory junction at the original file path. If an administrator restores the quarantined file, this can cause the file to be written to an arbitrary location, potentially enabling modification of protected files or SYSTEM-level code execution via DLL hijacking.
CVSS v4.0
Score 5.2medium
Affected software
WatchDog
Anti-Virus
pkg:github/watchdog/anti-virusRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from improper handling of symbolic links (directory junctions) before file access in the quarantine restoration feature of WatchDog Anti-Virus versions >=1.8.640 and <1.8.804 on Windows. A local attacker with low privileges can exploit this by creating a directory junction at the path of a quarantined file and then convincing an administrator to restore that file. The restoration process follows the link, causing the file to be written to an unintended location. This can lead to modification of protected system files or execution of code with SYSTEM privileges through DLL hijacking techniques.
Potential Impact
The vulnerability allows local low-privileged attackers to influence the location where quarantined files are restored by exploiting improper link resolution. This can result in unauthorized modification of protected files or enable SYSTEM-level code execution via DLL hijacking, potentially compromising system integrity and security.
Mitigation Recommendations
No official patch or fix is currently confirmed for this vulnerability. Users should check the vendor advisory for updates. Until a fix is available, administrators should exercise caution when restoring quarantined files, especially verifying the file paths and ensuring no suspicious directory junctions exist at those locations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- watchdog
- Date Reserved
- 2026-09-15T21:07:00.097Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aafd5d655bf5e2cf50c91e0
Added to database: 09/20/2026, 12:47:18 UTC
Last enriched: 09/20/2026, 13:01:29 UTC
Last updated: 09/20/2026, 13:01:29 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.