Junglewise Threat Intelligence

CVE-2026-9490: Acer Care Center denial of service in ACCSvc Named Pipe

CVE-2026-9490 · Severity: info · CVSS 6.8 · Published 2026-05-25

Vendors: Acer.

Executive brief

A security vulnerability has been identified in Acer Care Center, a support application pre-installed on Acer devices. An attacker with existing access to the computer can exploit this flaw to crash a background system service. This results in a local service disruption, preventing the support software from functioning correctly until it is restarted or updated.

Technical details

The Acer Care Center service (ACCSvc) creates a Named Pipe with an insecure Security Descriptor, leading to improper privilege management (CWE-269). An authenticated local attacker can connect to this pipe and transmit a specially crafted message (type 0x03). This causes the service to terminate unexpectedly with exit code 1067 (ERROR_PROCESS_ABORTED). The vulnerability is mitigated by updating Acer Care Center to the latest available version.

Affected products

  • Acer Care Center All versions prior to the latest update

Timeline

  • 2026-05-25: disclosed
  • 2026-05-25: advisory

References