Impact
The WatchDog Anti‑Virus installer mistakenly grants the Users group Full Control over its installation directory on Windows, allowing any local, non‑administrator user to alter, overwrite, or delete the antivirus binaries and configuration files. Because the malware binaries are loaded by an elevated WatchDog process, these changes can disable protection or cause privileged code execution. The vulnerability follows the poor privilege model detailed by CWE‑276.
Affected Systems
This flaw affects installations of WatchDog Anti‑Virus on Windows machines, specifically the directory C:\Program Files (x86)\Watchdog Anti‑Virus. No exact version numbers are listed, but all installations that used the original installer with the default permissions are vulnerable.
Risk and Exploitability
The CVSS base score of 5.9 indicates a medium severity condition. The EPSS information is currently not available and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs local, low‑privileged access with the ability to write to the Program Files directory, which is granted to the Users group by default. No additional exploitation steps beyond modifying the binaries are required. The resulting effect is a local privilege escalation that can remove or subvert anti‑virus functionality and potentially allow execution of malicious code with elevated privileges.
OpenCVE Enrichment