Impact
A vulnerability exists within the Acer System Monitoring component of NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user can access the service and modify registry entries, which may allow escalation of privileges to a higher level on the same workstation.
Affected Systems
Affected vendors include Acer, specifically the System Monitoring component bundled with NitroSense and PredatorSense. Systems running NitroSense versions earlier than 5.2.84, or PredatorSense versions earlier than 5.2.109, are vulnerable. The vulnerability applies to any installation that includes the privileged service with default access configurations.
Risk and Exploitability
The CVSS score of 7.4 classifies the vulnerability as high severity, and an EPSS score below 1% indicates a low but non-zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate locally to the system and then invoke the privileged service to perform unauthorized registry changes, leading to local privilege escalation.
OpenCVE Enrichment