Description
Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus. This may disable antivirus protection or enable privileged code execution if modified binaries are loaded by an elevated WatchDog process.
Published: 2026-09-20
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation enabling modification of antivirus binaries
Action: Urgent Update
AI Analysis

Impact

The WatchDog Anti‑Virus installer mistakenly grants the Users group Full Control over its installation directory on Windows, allowing any local, non‑administrator user to alter, overwrite, or delete the antivirus binaries and configuration files. Because the malware binaries are loaded by an elevated WatchDog process, these changes can disable protection or cause privileged code execution. The vulnerability follows the poor privilege model detailed by CWE‑276.

Affected Systems

This flaw affects installations of WatchDog Anti‑Virus on Windows machines, specifically the directory C:\Program Files (x86)\Watchdog Anti‑Virus. No exact version numbers are listed, but all installations that used the original installer with the default permissions are vulnerable.

Risk and Exploitability

The CVSS base score of 5.9 indicates a medium severity condition. The EPSS information is currently not available and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs local, low‑privileged access with the ability to write to the Program Files directory, which is granted to the Users group by default. No additional exploitation steps beyond modifying the binaries are required. The resulting effect is a local privilege escalation that can remove or subvert anti‑virus functionality and potentially allow execution of malicious code with elevated privileges.

Generated by OpenCVE AI on September 20, 2026 at 13:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WatchDog Anti‑Virus to the latest release listed in the official release notes, which corrects the directory permissions.
  • If an update is not immediately possible, manually change the ACL on C:\Program Files (x86)\Watchdog Anti‑Virus to remove Full Control rights from the Users group and grant access only to Administrators.
  • Continuously monitor the integrity of the antivirus binaries and configuration files to detect unauthorized modifications, and remediate promptly if changes are observed.

Generated by OpenCVE AI on September 20, 2026 at 13:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Watchdog
Watchdog anti-virus
Vendors & Products Watchdog
Watchdog anti-virus

Sun, 20 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus. This may disable antivirus protection or enable privileged code execution if modified binaries are loaded by an elevated WatchDog process.
Title Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/RE:M/U:Amber'}


Subscriptions

Watchdog Anti-virus
cve-icon MITRE

Status: PUBLISHED

Assigner: watchdog

Published:

Updated: 2026-09-20T12:16:45.612Z

Reserved: 2026-09-15T21:06:50.338Z

Link: CVE-2026-92252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T13:17:46.063

Modified: 2026-09-20T13:17:46.063

Link: CVE-2026-92252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:30:17Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions