CVE-2026-50609: Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acer System Monitoring component (included with NitroSense and PredatorSense)to a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
Acer System Monitoring component (included with NitroSense and PredatorSense)to a version that resolves this vulnerability.Fixed in 5.2.109
Event History
Frequently Asked Questions
Which installations are in scope?
The affected component is Acer System Monitoring as included with NitroSense and PredatorSense software.
What access does an attacker need?
Exploitation requires an authenticated local user. The issue is associated with a privileged Named Pipe service that can permit unauthorized registry operations.
What is the potential impact?
In certain situations, the unauthorized registry operations could lead to privilege escalation or compromise of the affected system.