CVE-2025-41698

7.8

Draeger · Draeger ICMHelper

A missing authorization vulnerability in Draeger ICMHelper allows low privileged local attackers to interact with the service, bypassing intended user interaction restrictions.

Executive summary

A missing authorization vulnerability in Draeger ICMHelper allows a low privileged local attacker to gain full control over the service, posing a high risk to system integrity and availability.

Vulnerability

This is a missing authorization flaw (CWE-862) occurring within the Draeger ICMHelper service. The vulnerability allows an attacker with low local privileges to interact with the service without the required authorization checks, effectively bypassing intended security controls.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows a local attacker to achieve total impact on the confidentiality, integrity, and availability of the affected system, which could lead to unauthorized data access or disruption of critical medical monitoring operations.

Remediation

Immediate Action: Organizations should review the official vendor advisory at https://certvde.com/en/advisories/VDE-2025-028 and apply any available security updates provided by Draeger to remediate this authorization flaw.

Proactive Monitoring: Security teams should monitor local system access logs for anomalous interactions with the ICMHelper service, particularly those originating from user accounts with restricted permissions.

Compensating Controls: Implement strict principle of least privilege policies on the host operating system to limit the number of local users capable of interacting with sensitive service binaries.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for total system impact, it is imperative that administrators identify all instances of Draeger ICMHelper within their environment. Organizations must track the vendor advisory for patch availability and prioritize the deployment of fixes as soon as they are released to prevent local privilege escalation and service manipulation.

Sources

Originally found and disclosed by CODE WHITE GmbH, per the CVE Program record.