CVE-2026-50603: Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NitroSenseto a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
PredatorSenseto a version that resolves this vulnerability.Fixed in 5.2.109
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a local attacker under certain circumstances. The provided information does not indicate that it can be exploited remotely.
What could an attacker do with the embedded encryption key?
An attacker may be able to use the hard-coded AES key to access protected information or perform unauthorized actions. The specific protected data and actions are not identified in the provided information.