NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
Advisories
No advisories yet.
Fixes
Solution
Please update for version 3.01.3056.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19652 |
|
History
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acer
Acer nitrosense V3 |
|
| Vendors & Products |
Acer
Acer nitrosense V3 |
Mon, 25 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges. | |
| Title | NitroSense V3: Local Privilege Escalation (LPE) vulnerability | |
| Weaknesses | CWE-22 CWE-269 CWE-284 CWE-732 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-05-25T01:50:32.063Z
Reserved: 2026-05-25T01:34:16.727Z
Link: CVE-2026-9489
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:07Z