---
cve: "CVE-2026-92254"
severity: "MEDIUM"
cvss: 6.9
epss: "2.6%"
vendor: "Watchdog"
kev: false
exploited: false
published: "2026-09-20 13:17:46"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T00:28:34+02:00"
---

# CVE-2026-92254

> 6.9 MEDIUM

## Beschreibung

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling security products or destabilizing the operating system, via crafted IOCTL requests sent to the \Device\wsdk device.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/RE:L/U:Amber
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://watchdog.com/vulnerability-disclosure-policy/>
- <https://watchdog.com/anti-virus-release-notes/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-92254) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
