PT-2026-95964 · Watchdog · Watchdog Anti-Virus
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:Amber |
Name of the Vulnerable Software and Affected Versions
Watchdog WatchDog Antivirus version 1.8.640 (driver versions 1.3.0.0 and earlier)
Description
Missing authorization in the IOCTL handlers of the
wsdkd.sys kernel drivers allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges. This is achieved by sending crafted IOCTL requests to the Devicewsdk endpoint, which enables the bypass of NTFS access controls and can lead to the disabling of security products or operating system instability.Recommendations
Update the
wsdkd.sys driver to a version later than 1.3.0.0.Fix
Missing Authentication
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Watchdog Anti-Virus