PT-2026-3281 · Acer · Acer Updater Service

·

CVE-2021-47825

·

Published

2026-01-16

·

Updated

2026-01-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Acer Updater Service version 1.2.3500.0
Description The Acer Updater Service contains a flaw due to an unquoted service path. This allows local users to potentially execute code with elevated system privileges. An attacker can exploit the unquoted path located in 'C:Program FilesAcerAcer Updater' by injecting malicious executables. These executables will then run with LocalSystem permissions when the service starts.
Recommendations Apply appropriate quoting to the service path to prevent the execution of unauthorized code.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47825

Affected Products

Acer Updater Service