Impact
Missing authorization checks in the IOCTL handlers of the wsdkd.sys kernel driver allow a local attacker with low privileges to send crafted IOCTL requests to the \Device\wsdk device. The driver then executes the request with SYSTEM privileges, bypassing NTFS access controls. This enables the attacker to delete arbitrary files, which can disable security products or destabilize the operating system. The vulnerability is rooted in improper input validation (CWE‑20) and missing authentication (CWE‑306).
Affected Systems
WatchDog Antivirus 1.8.640 and earlier driver versions (1.3.0.0 and earlier) running on Microsoft Windows are affected. The vulnerability resides in the kernel driver and may impact any system that has the Attack‑detection software installed.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The exploitation requires local access to the affected machine; an attacker must have the ability to run code on the host to issue the IOCTL requests. Once executed, the attacker obtains SYSTEM privileges through the driver and can delete critical files, bypass NTFS protections, and potentially shut down security functions or destabilize the OS.
OpenCVE Enrichment