PT-2026-3281 · Acer · Acer Updater Service

Emmanuel Lujan

·

Published

2026-01-16

·

Updated

2026-01-17

·

CVE-2021-47825

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Acer Updater Service version 1.2.3500.0
Description The Acer Updater Service contains a flaw due to an unquoted service path. This allows local users to potentially execute code with elevated system privileges. An attacker can exploit the unquoted path located in 'C:Program FilesAcerAcer Updater' by injecting malicious executables. These executables will then run with LocalSystem permissions when the service starts.
Recommendations Apply appropriate quoting to the service path to prevent the execution of unauthorized code.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-47825

Affected Products

Acer Updater Service