Executive brief
Acer NitroSense, a utility used to monitor and manage system performance on Acer laptops, contains a security flaw that allows a standard user to gain full administrative control. By exploiting a misconfigured communication channel within the software, an attacker who already has basic access to the computer can execute commands or delete files with the highest level of system privileges. This could lead to a complete takeover of the device or the destruction of critical system data.
Technical details
Acer NitroSense versions 3.x prior to 3.01.3052 expose a Windows Named Pipe that utilizes a custom protocol for invoking internal functions. This Named Pipe is improperly secured, allowing any authenticated local user to interact with it. An attacker can leverage this misconfiguration to execute arbitrary code or delete arbitrary files with NT AUTHORITY\SYSTEM privileges. The vulnerability involves multiple weaknesses including improper access control (CWE-284), incorrect permission assignment (CWE-732), and path traversal (CWE-22). Users should update to version 3.01.3052 or later to mitigate this risk.
Affected products
- Acer NitroSense 3.x before 3.01.3052
Timeline
- 2026-05-24: disclosed: Initial disclosure by Acer
- 2026-05-25: advisory: NVD publication date