Executive brief
A security vulnerability in Acer NitroSense, a utility used to monitor and manage system performance on Acer laptops, could allow a local user to delete critical system files. By exploiting a flaw in how the software handles internal communication, an individual with basic access to the computer can execute commands with high-level administrative privileges. This could lead to system instability, data loss, or a complete system crash.
Technical details
A Local Privilege Escalation (LPE) vulnerability exists in the PSAdminAgent service of Acer NitroSense versions prior to 3.01.3052. The service creates a Named Pipe with a weak Access Control List (ACL), allowing any authenticated local user to connect and issue commands. The service fails to validate the caller's privilege level before executing file deletion operations. Consequently, a low-privileged attacker can leverage this communication channel to delete arbitrary files with SYSTEM-level permissions. The vulnerability is tracked as CVE-2026-9789 and includes elements of path traversal (CWE-22) and improper privilege management (CWE-269).
Affected products
- Acer NitroSense prior to 3.01.3052
Timeline
- 2026-05-28: advisory: NVD publication date
- 2026-05-27: disclosed: Initial disclosure by Acer