CVE-2026-9489 Details
Description
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
A local privilege escalation vulnerability has been identified in Acer NitroSense versions 3.x prior to 3.01.3052. The issue arises because the application exposes a Windows Named Pipe that, while intended for internal function calls, is misconfigured. This flaw allows any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete files with SYSTEM privileges. Exploiting this vulnerability could enable an attacker to gain elevated rights and execute unauthorized actions on the affected system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.acer.com/en/kb/articles/19652 | Acer |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Acer |
| CWE-269 | Improper Privilege Management | Acer |
| CWE-284 | Improper Access Control | Acer |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | Acer |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Acer |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | Acer |