PT-2026-42992 · Acer · Nitrosense

·

CVE-2026-9489

·

Published

2026-05-25

·

Updated

2026-05-25

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NitroSense versions 3.x through 3.01.3051
Description The software contains a Local Privilege Escalation (LPE) issue where a Windows Named Pipe, which uses a custom protocol to invoke internal functions, is misconfigured. This allows any authenticated local user to execute arbitrary code and delete arbitrary files with NT AUTHORITYSYSTEM privileges, leading to full system compromise with elevated privileges.
Recommendations Update to version 3.01.3052.

Fix

LPE

Incorrect Permission

Path traversal

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9489

Affected Products

Nitrosense