Impact
The Acer Agent Service component in NitroSense and PredatorSense implements insufficient access controls for a privileged service. An authenticated local user can execute registry operations that the service should not permit, allowing modification of critical system settings or registry entries, which can be leveraged to elevate privileges or otherwise compromise the host, thereby enabling further malicious actions.
Affected Systems
The vulnerability affects Acer Agent Service bundled with NitroSense and PredatorSense, with all releases that do not include NitroSense version 5.2.84 or newer and PredatorSense version 5.2.109 or newer. Systems running these older versions are susceptible until the recommended updates are applied.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Potential attackers would need local authenticated access, which is the likely attack vector. If successful, the impact would be privilege escalation that could give an attacker full control over the affected system.
OpenCVE Enrichment