Junglewise Threat Intelligence

CVE-2026-9489: Acer NitroSense privilege escalation via Windows Named Pipe

CVE-2026-9489 · Severity: info · CVSS 8.5 · Published 2026-05-25

Technologies: Acer NitroSense. Vendors: Acer.

Executive brief

Acer NitroSense, a utility used to monitor and manage system performance on Acer laptops, contains a security flaw that allows a standard user to gain full administrative control. By exploiting a misconfigured communication channel within the software, an attacker who already has basic access to the computer can execute commands or delete files with the highest level of system privileges. This could lead to a complete takeover of the device or the destruction of critical system data.

Technical details

Acer NitroSense versions 3.x prior to 3.01.3052 expose a Windows Named Pipe that utilizes a custom protocol for invoking internal functions. This Named Pipe is improperly secured, allowing any authenticated local user to interact with it. An attacker can leverage this misconfiguration to execute arbitrary code or delete arbitrary files with NT AUTHORITY\SYSTEM privileges. The vulnerability involves multiple weaknesses including improper access control (CWE-284), incorrect permission assignment (CWE-732), and path traversal (CWE-22). Users should update to version 3.01.3052 or later to mitigate this risk.

Affected products

  • Acer NitroSense 3.x before 3.01.3052

Timeline

  • 2026-05-24: disclosed: Initial disclosure by Acer
  • 2026-05-25: advisory: NVD publication date

References

Related threats