Executive brief
Dräger Protector Software, used for managing respiratory protection equipment and safety data, contains a security flaw that could allow a local user to gain full control over the host computer. By exploiting weak file permissions, an attacker can replace legitimate software components with malicious ones. This allows them to execute unauthorized commands with the highest level of system administrative privileges, potentially leading to a complete compromise of the workstation and its data.
Technical details
A local privilege escalation vulnerability exists in Dräger Protector Software versions prior to 6.4.2 due to incorrect permission assignment for critical resources (CWE-732). The software's file system permissions are configured insecurely, allowing a local attacker to overwrite or replace application binaries or loaded modules. Because these components may be executed by services with high-level permissions, an attacker can achieve code execution with NT AUTHORITY\SYSTEM privileges. Exploitation requires local access to the host system and may involve minimal user interaction. The issue is resolved in version 6.4.2.
Affected products
- Dräger Protector Software < 6.4.2
Timeline
- 2026-06-02: advisory: NVD and VulnCheck published the advisory details.
- 2026-06-02: disclosed