Executive brief
Acer Agent Service is a privileged system component included with gaming software (NitroSense and PredatorSense) that manages performance settings. A flaw in access controls allows an authenticated local user to make unauthorized changes to the Windows registry, potentially leading to privilege escalation or system compromise.
Technical details
The vulnerability is an insufficient access control issue in a privileged Windows service (Acer Agent Service). An authenticated local attacker can perform unauthorized registry operations by exploiting weak access checks in the service. This precondition—local authentication and access to the system—is typical of privilege escalation attacks. By modifying critical registry entries through the privileged service, an attacker could escalate their privileges or alter system configuration to compromise the affected machine. No patch information is currently available.
Affected products
- Acer NitroSense <UNKNOWN>
- Acer PredatorSense <UNKNOWN>
Timeline
- 2026-09-17: disclosed