Executive brief
NitroSense and PredatorSense are system monitoring utilities bundled with Acer gaming computers. A flaw in access controls allows an authenticated local user to modify Windows registry settings without proper authorization, potentially gaining administrative privileges on the machine.
Technical details
The vulnerability stems from insufficient access controls in the Acer System Monitoring privileged service. An authenticated local attacker can interact with the service and perform unauthorized registry modifications. This is a local privilege escalation vector requiring authentication and local code execution capability. Patches are expected from Acer; check the community KB for remediation guidance.
Affected products
- Acer NitroSense <UNKNOWN>
- Acer PredatorSense <UNKNOWN>
Timeline
- 2026-09-17: disclosed