PT-2026-42992 · Acer · Nitrosense
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NitroSense versions 3.x through 3.01.3051
Description
The software contains a Local Privilege Escalation (LPE) issue where a Windows Named Pipe, which uses a custom protocol to invoke internal functions, is misconfigured. This allows any authenticated local user to execute arbitrary code and delete arbitrary files with NT AUTHORITYSYSTEM privileges, leading to full system compromise with elevated privileges.
Recommendations
Update to version 3.01.3052.
Fix
LPE
Incorrect Permission
Path traversal
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nitrosense