NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19652 |
|
History
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acer
Acer nitrosense V3 |
|
| Vendors & Products |
Acer
Acer nitrosense V3 |
Mon, 25 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges. | |
| Title | NitroSense V3: Local Privilege Escalation (LPE) vulnerability | |
| Weaknesses | CWE-22 CWE-269 CWE-284 CWE-732 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Acer
Published: 2026-05-25T01:50:32.063Z
Updated: 2026-05-26T15:20:21.624Z
Reserved: 2026-05-25T01:34:16.727Z
Link: CVE-2026-9489
Updated: 2026-05-26T15:20:17.099Z
Status : Awaiting Analysis
Published: 2026-05-25T02:16:57.773
Modified: 2026-05-26T19:05:09.927
Link: CVE-2026-9489
No data.