A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
This issue is resolved in NitroSense versions V3.01.3056.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19670 |
|
History
Thu, 28 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority. | |
| Title | NitroSense V3: Security Vulnerability Information | |
| Weaknesses | CWE-22 CWE-269 CWE-284 CWE-732 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-05-28T02:39:40.930Z
Reserved: 2026-05-28T02:16:31.420Z
Link: CVE-2026-9789
No data.
Status : Received
Published: 2026-05-28T03:16:44.200
Modified: 2026-05-28T03:16:44.200
Link: CVE-2026-9789
No data.
OpenCVE Enrichment
Updated: 2026-05-28T04:45:07Z