Executive brief
Acer's System Monitoring component, included in NitroSense and PredatorSense software, contains insufficient access controls in a privileged system service. An authenticated local user could exploit this to perform unauthorized registry operations, potentially gaining elevated system privileges or fully compromising the affected computer.
Technical details
The vulnerability is an insufficient access control issue in a privileged Named Pipe service within Acer's System Monitoring component. An authenticated local attacker can perform unauthorized registry operations through the inadequately protected Named Pipe interface. The attack requires local system access and an active user session. Successful exploitation could result in privilege escalation or complete system compromise. Patch availability is unknown based on available information.
Affected products
- Acer NitroSense
- Acer PredatorSense
Timeline
- 2026-09-17: disclosed