PT-2026-38677 · Acer · Predatorsense

Artem Domarev

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-8069

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions PredatorSense versions 3.00.3136 through 3.00.3196
Description A misconfigured Windows Named Pipe uses a custom protocol to invoke internal functions. This allows any authenticated local user to execute arbitrary code and delete arbitrary files with NT AUTHORITYSYSTEM privileges, leading to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Access Control

Incorrect Permission

Improper Privilege Management

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-8069

Affected Products

Predatorsense