← All Advisories

Dräger Protector Software insecure file permissions allow local attacker to replace binaries and execute code as SYSTEM

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2021-4481

Key Details

CVECVE-2021-4481
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-07-22
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is none; integrity impact is high; availability impact is high.
Classified asCWE-732 (Incorrect Permission Assignment for Critical Resource)

What to Know

Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2021-4481
CVEhttps://www.cve.org/CVERecord?id=CVE-2021-4481