{"id":"CVE-2026-92253","title":"Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem locat…","summary":"Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem locat…","severity":"medium","cvss":5.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/RE:L/U:Green","cwe":["CWE-59"],"vendor":"WatchDog","product":"Anti-Virus","affected":["Anti-Virus >= 1.8.640 < 1.8.804"],"published":"2026-09-20","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:17:34.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92253","references":[{"url":"https://watchdog.com/anti-virus-release-notes/","label":"34edf4f2-2577-40ab-82ce-39f45972c129"},{"url":"https://watchdog.com/vulnerability-disclosure-policy/","label":"34edf4f2-2577-40ab-82ce-39f45972c129"}],"tags":["nvd","cve.org"],"epss":0.00131,"epssPercentile":0.03101,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T14:11:52.365935Z"},"cvssSource":"cna","ingestedAt":"2026-09-20T13:21:45.082Z","slug":"CVE-2026-92253","body":"## Overview\n\nImproper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a directory junction at the original file path and persuading an administrator to restore the file. This may enable modification of protected files or SYSTEM-level code execution through DLL hijacking.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":28.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}