Impact
A vulnerability exists in the Acer Agent Service that embeds a hard‑coded AES encryption key. Because the key is permanently stored in the binary, a local attacker who can execute code on the host can extract the key and decrypt data or manipulate protected functions, thereby gaining unauthorized access or persistence. The weakness corresponds to improper key management (CWE‑321) and can lead to confidentiality and integrity violations for data handled by the service.
Affected Systems
The issue affects the Acer Agent Service component bundled with NitroSense and PredatorSense. Specifically, versions prior to NitroSense 5.2.84 and PredatorSense 5.2.109 contain the hard‑coded key. Organisms running these versions expose the Agent Service to potential local exploitation; the impact scope is limited to local hosts where the service runs with elevated privileges.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of < 1 % suggests low current exploitation probability. The vulnerability is not currently listed in CISA KEV. An attacker must be able to run code locally on the affected machine—typically a user who has administrative permissions or has already achieved privilege escalation. Once the key is extracted, the attacker can decrypt sensitive logs or tamper with configuration, giving them capacity for unauthorized actions on the host.
OpenCVE Enrichment