Executive brief
A security vulnerability has been identified in Acer Care Center, a support application pre-installed on Acer devices. An attacker with existing access to the computer can exploit this flaw to crash a background system service. This results in a local service disruption, preventing the support software from functioning correctly until it is restarted or updated.
Technical details
The Acer Care Center service (ACCSvc) creates a Named Pipe with an insecure Security Descriptor, leading to improper privilege management (CWE-269). An authenticated local attacker can connect to this pipe and transmit a specially crafted message (type 0x03). This causes the service to terminate unexpectedly with exit code 1067 (ERROR_PROCESS_ABORTED). The vulnerability is mitigated by updating Acer Care Center to the latest available version.
Affected products
- Acer Care Center All versions prior to the latest update
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory