Executive brief
Dräger Protector Software, used for managing respiratory protection equipment and maintenance records, contains a security flaw that could allow a local user to gain full control over the host computer. By exploiting weak file permissions, an attacker with basic access to the system can replace legitimate software files with malicious ones. This could lead to a total compromise of the workstation, allowing unauthorized software execution and potential disruption of safety equipment management operations.
Technical details
A local privilege escalation vulnerability exists in Dräger Protector Software versions prior to 6.4.2 due to incorrect permission assignment for critical resources (CWE-732). The software's installation directory or specific sub-components utilize insecure file system permissions, allowing non-privileged local users to modify or replace executable binaries and loaded modules. An attacker can exploit this by overwriting a legitimate service binary or DLL with a malicious payload. When the software or its associated services are subsequently executed by the system, the attacker's code runs with elevated NT AUTHORITY\SYSTEM privileges. The vulnerability is remediated in version 6.4.2.
Affected products
- Dräger Protector Software prior to 6.4.2
Timeline
- 2026-06-02: advisory: NVD and VulnCheck published advisory details.
- 2026-06-02: disclosed