← back
CVE-2021-4481

Dräger Protector Software Local Privilege Escalation via Insecure File Permissions

CVSS 8.3 HIGHEPSS 0.1%CWE-732
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.3EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
02 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →