Impact
A privilege‑based Named Pipe service in the Acer System Monitoring component of NitroSense and PredatorSense allows an authenticated local user to perform unauthorized registry operations. The flaw is an insufficient access control that can be abused to modify registry keys, potentially enabling privilege escalation or full system compromise. The weakness is identified by CWE‑284, reflecting a failure to enforce proper authorization checks for privileged actions.
Affected Systems
The vulnerability affects versions of NitroSense and PredatorSense that include the Acer System Monitoring component and are older than NitroSense v5.2.84 and PredatorSense v5.2.109. Systems running those earlier releases should be considered at risk, regardless of operating system.
Risk and Exploitability
The vulnerability has a CVSS score of 7.4, indicating high severity, but the EPSS score is below 1 %, suggesting that exploitation attempts are rare. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires an authenticated user, but the impact—unauthorized registry modification and possible elevation of privileges—remains significant. The risk is elevated for environments where local users possess elevated rights or where the component is widely deployed, despite the low probability of widespread exploitation.
OpenCVE Enrichment