CVE-2026-9490 Details
Description
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). To mitigate this potential local service disruption, Acer requires users to update the software to the latest version.
A vulnerability exists in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This flaw allows an authenticated local user to connect to the pipe and send a specially crafted message, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). Users are advised to update the software to the latest version to prevent this local service disruption.
Users are recommended to update Acer Care Center to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.acer.com/en/kb/articles/19668 | Acer | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | Acer |
Affected Products
| Product | Versions |
|---|---|
| acer care center | < 4.00.3060 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Acer |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| May 25, 2026 | New CVE Received | Acer |