CVE-2021-4480

HIGH

Dräger Protector Software Local Privilege Escalation via Insecure File Permissions

Title source: cna
STIX 2.1

Description

Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.

Scores

CVSS v3 8.2
EPSS 0.0011
EPSS Percentile 1.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
Dräger/Protector Software < 6.4.2
Published Jun 02, 2026
Tracked Since Jun 03, 2026