CVE-2021-4480 HIGH

CVE-2021-4480: Dräger Protector Software Local Privilege Escalation via Insecure File Permissions

Vendor Dräger
Product Protector Software
Weakness CWE-732
Published June 2, 2026
Last update June 3, 2026

CVSS base score

8.3/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

What the vulnerability does

01Description

Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.

Key dates

02Disclosure timeline

June 2, 2026 CVE published
June 3, 2026 Record updated