Description
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The Acer Agent Service component in NitroSense and PredatorSense implements insufficient access controls for a privileged service. An authenticated local user can execute registry operations that the service should not permit, allowing modification of critical system settings or registry entries, which can be leveraged to elevate privileges or otherwise compromise the host, thereby enabling further malicious actions.

Affected Systems

The vulnerability affects Acer Agent Service bundled with NitroSense and PredatorSense, with all releases that do not include NitroSense version 5.2.84 or newer and PredatorSense version 5.2.109 or newer. Systems running these older versions are susceptible until the recommended updates are applied.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Potential attackers would need local authenticated access, which is the likely attack vector. If successful, the impact would be privilege escalation that could give an attacker full control over the affected system.

Generated by OpenCVE AI on September 18, 2026 at 00:52 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Update NitroSense to version 5.2.84 or later
  • Update PredatorSense to version 5.2.109 or later
  • Restrict local privilege levels and ensure users do not have unnecessary access to the Acer Agent Service
  • If an update is not immediately available, consider disabling the Acer Agent Service until the fix is applied

Generated by OpenCVE AI on September 18, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer agent Service
Vendors & Products Acer
Acer agent Service

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.
Title Privilege Escalation Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


Subscriptions

Acer Agent Service
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:31:34.878Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50605

cve-icon Vulnrichment

Updated: 2026-09-17T12:31:31.114Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T08:17:01.010

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:30:14Z

Weaknesses