Description
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in local privilege escalation.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

A vulnerability exists within the Acer System Monitoring component of NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user can access the service and modify registry entries, which may allow escalation of privileges to a higher level on the same workstation.

Affected Systems

Affected vendors include Acer, specifically the System Monitoring component bundled with NitroSense and PredatorSense. Systems running NitroSense versions earlier than 5.2.84, or PredatorSense versions earlier than 5.2.109, are vulnerable. The vulnerability applies to any installation that includes the privileged service with default access configurations.

Risk and Exploitability

The CVSS score of 7.4 classifies the vulnerability as high severity, and an EPSS score below 1% indicates a low but non-zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate locally to the system and then invoke the privileged service to perform unauthorized registry changes, leading to local privilege escalation.

Generated by OpenCVE AI on September 18, 2026 at 00:27 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Upgrade NitroSense to version 5.2.84 or later.
  • Upgrade PredatorSense to version 5.2.109 or later.
  • Limit local user permissions to prevent modification of the System Monitoring privileged service if upgrade is delayed.

Generated by OpenCVE AI on September 18, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer system Monitoring
Vendors & Products Acer
Acer system Monitoring

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in local privilege escalation.
Title Improper Access control Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


Subscriptions

Acer System Monitoring
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:18:12.672Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50610

cve-icon Vulnrichment

Updated: 2026-09-17T12:16:34.470Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T09:16:41.487

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:43Z

Weaknesses