<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Kiosk Escape — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/kiosk-escape/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 01 Jun 2026 23:16:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/kiosk-escape/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2019-25718: Dräger Infinity Explorer C700 Kiosk Escape Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-06-draeger-privesc/</link><pubDate>Mon, 01 Jun 2026 23:16:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-06-draeger-privesc/</guid><description>Dräger Infinity Explorer C700 contains a privilege escalation vulnerability (CVE-2019-25718) that allows attackers to break out of kiosk mode, access the underlying operating system, and potentially cause the device to display incorrect patient monitor information.</description><content:encoded><![CDATA[<p>Dräger Infinity Explorer C700 is vulnerable to a privilege escalation (CVE-2019-25718) stemming from a flaw in the kiosk mode implementation. An attacker can exploit this vulnerability via a specific dialog interaction to escape the kiosk environment and gain access to the underlying operating system. This access can then be leveraged to manipulate the device, potentially leading to the display of incorrect or no information from the connected Delta Family patient monitor. The vulnerability allows an attacker to gain control of the operating system, which impacts the integrity of displayed medical data.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker gains physical or remote access to a Dräger Infinity Explorer C700 device.</li>
<li>The attacker interacts with a specific dialog within the kiosk mode application.</li>
<li>Through a series of interactions (details unspecified in source), the attacker triggers the privilege escalation vulnerability (CVE-2019-25718).</li>
<li>The attacker successfully escapes the kiosk mode environment.</li>
<li>The attacker gains access to the underlying operating system.</li>
<li>The attacker uses the elevated privileges to modify system settings or install malicious software.</li>
<li>The attacker manipulates the data displayed by the device from the connected Delta Family patient monitor.</li>
<li>The device displays incorrect, or no information to medical personnel.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2019-25718 allows an attacker to break out of kiosk mode on a Dräger Infinity Explorer C700 device, gaining access to the underlying operating system. This could lead to the display of incorrect or missing information from the connected Delta Family patient monitor, potentially affecting patient care and safety. The number of affected devices or specific sectors targeted is not specified in the provided source.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement strict physical access controls to the Dräger Infinity Explorer C700 devices to prevent unauthorized access and initial exploitation.</li>
<li>Monitor process creations for unusual processes running outside of the expected kiosk application scope.</li>
<li>Monitor network connections for suspicious outbound traffic originating from the Dräger Infinity Explorer C700 devices using the Sigma rule &ldquo;Detect Unusual Network Connection from Medical Device&rdquo;.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>cve-2019-25718</category><category>kiosk escape</category><category>medical device</category></item></channel></rss>