Description
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Published: 2026-09-17
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality and integrity compromise via hard‑coded key
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in the Acer Agent Service that embeds a hard‑coded AES encryption key. Because the key is permanently stored in the binary, a local attacker who can execute code on the host can extract the key and decrypt data or manipulate protected functions, thereby gaining unauthorized access or persistence. The weakness corresponds to improper key management (CWE‑321) and can lead to confidentiality and integrity violations for data handled by the service.

Affected Systems

The issue affects the Acer Agent Service component bundled with NitroSense and PredatorSense. Specifically, versions prior to NitroSense 5.2.84 and PredatorSense 5.2.109 contain the hard‑coded key. Organisms running these versions expose the Agent Service to potential local exploitation; the impact scope is limited to local hosts where the service runs with elevated privileges.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, and the EPSS score of < 1 % suggests low current exploitation probability. The vulnerability is not currently listed in CISA KEV. An attacker must be able to run code locally on the affected machine—typically a user who has administrative permissions or has already achieved privilege escalation. Once the key is extracted, the attacker can decrypt sensitive logs or tamper with configuration, giving them capacity for unauthorized actions on the host.

Generated by OpenCVE AI on September 17, 2026 at 21:10 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Install the latest NitroSense or PredatorSense versions (v5.2.84 or v5.2.109) to replace the hard‑coded key.
  • Restrict the Acer Agent Service to run only under a dedicated, non‑privileged local account and remove unnecessary local administrative privileges.
  • Continuously audit the Service configuration and file permissions to ensure the binary is not tampered with and that no additional hard‑coded keys are introduced.

Generated by OpenCVE AI on September 17, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer agent Service
Vendors & Products Acer
Acer agent Service

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Title Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer Agent Service
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T14:48:17.751Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50603

cve-icon Vulnrichment

Updated: 2026-09-17T14:48:09.377Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T04:17:46.930

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key