---
id: CVE-2026-92254
title: "Missing Authorization in the IOCTL handlers of the\_wsdkd.sys\_kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…"
summary: "Missing Authorization in the IOCTL handlers of the\_wsdkd.sys\_kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…"
severity: medium
cvss: 6.9
cvssVector: >-
  CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/RE:L/U:Amber
cwe:
  - CWE-20
  - CWE-306
vendor: Watchdog
product: Anti-Virus
affected:
  - Anti-Virus >= 1.8.640 < 1.8.804
published: '2026-09-20'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92254'
references:
  - url: 'https://watchdog.com/anti-virus-release-notes/'
    label: 34edf4f2-2577-40ab-82ce-39f45972c129
  - url: 'https://watchdog.com/vulnerability-disclosure-policy/'
    label: 34edf4f2-2577-40ab-82ce-39f45972c129
tags:
  - nvd
  - cve.org
epss: 0.00141
epssPercentile: 0.02778
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T14:16:20.582346Z'
cvssSource: cna
ingestedAt: '2026-09-20T13:21:45.082Z'
---

## Overview

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling security products or destabilizing the operating system, via crafted IOCTL requests sent to the \Device\wsdk device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
