Description
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

A privilege‑based Named Pipe service in the Acer System Monitoring component of NitroSense and PredatorSense allows an authenticated local user to perform unauthorized registry operations. The flaw is an insufficient access control that can be abused to modify registry keys, potentially enabling privilege escalation or full system compromise. The weakness is identified by CWE‑284, reflecting a failure to enforce proper authorization checks for privileged actions.

Affected Systems

The vulnerability affects versions of NitroSense and PredatorSense that include the Acer System Monitoring component and are older than NitroSense v5.2.84 and PredatorSense v5.2.109. Systems running those earlier releases should be considered at risk, regardless of operating system.

Risk and Exploitability

The vulnerability has a CVSS score of 7.4, indicating high severity, but the EPSS score is below 1 %, suggesting that exploitation attempts are rare. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires an authenticated user, but the impact—unauthorized registry modification and possible elevation of privileges—remains significant. The risk is elevated for environments where local users possess elevated rights or where the component is widely deployed, despite the low probability of widespread exploitation.

Generated by OpenCVE AI on September 18, 2026 at 00:50 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Apply the vendor’s recommended update: upgrade NitroSense to version 5.2.84 or PredatorSense to version 5.2.109 or later.
  • Confirm the affected Named Pipe service has correct ACLs; restrict local user access to authorized processes only.
  • Enable auditing of registry modifications and monitor for unexpected changes to keys written by the Acer System Monitoring component.

Generated by OpenCVE AI on September 18, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer system Monitoring
Vendors & Products Acer
Acer system Monitoring

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.
Title Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


Subscriptions

Acer System Monitoring
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:24:11.273Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50609

cve-icon Vulnrichment

Updated: 2026-09-17T12:23:58.785Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T09:16:41.370

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:46Z

Weaknesses