CVE-2026-50610: Improper Access control Vulnerability in NitroSense and PredatorSense Software
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in local privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acer System Monitoring component (NitroSense/PredatorSense)to a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
Acer System Monitoring component (NitroSense/PredatorSense)to a version that resolves this vulnerability.Fixed in 5.2.109
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated local user. The issue is in a privileged service within the Acer System Monitoring component.
What access could an attacker gain through exploitation?
The attacker may be able to make unauthorized registry modifications through the service. This could potentially result in local privilege escalation.
Which systems should be reviewed?
Review systems with Acer NitroSense or Acer PredatorSense installed, particularly where the Acer System Monitoring component is present.