Vulnerability
Published 2026-09-29
Verified 2026-10-04

Acer NitroSense/PredatorSense CVE-2026-50610 (CVSS 4.0 7.4): System Monitor named pipe → SYSTEM registry write / LPE

CVE-2026-50610 (CVE.org record updated 17 September 2026; Intrinsec public write-up 29 September 2026) is a local privilege-escalation flaw in the Acer System Monitoring component shipped with NitroSense and PredatorSense. Insufficient access control on a privileged Windows service (AcerSysHardwareService / systemmonitoring_hardware_service_ named pipe writable by Authenticated Users) lets an authenticated local user trigger unauthorized registry modifications as SYSTEM (CWE-284). Intrinsec’s research chain writes a utilman debugger value and obtains NT AUTHORITY\SYSTEM from the login-screen accessibility path. CVE.org CVSS 4.0 7.4 HIGH (AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U); product status lists affected through 1.0.19.2. Intrinsec notes tested AcerSysHardwareService.exe builds 1.0.1018.13 / 1.0.1019.0 (NitroSense 5.1.361 engine). Vendor remediation pointer: Acer Community KB article 19877 (apply Acer advisory update or disable/uninstall the affected service). No wild exploitation stated. Primary: CVE.org; research: Intrinsec 29 Sep; Talkback resurfaced ~2 Oct.

Product
Acer System Monitoring / NitroSense / PredatorSense (AcerSysHardwareService)
Versions
CVE.org: affected through 1.0.19.2. Intrinsec tested AcerSysHardwareService.exe 1.0.1018.13 / 1.0.1019.0 (NitroSense 5.1.361). Apply Acer KB 19877 update or disable/uninstall the vulnerable service.
CVSS
Exploited in Australia?
unknown
Patch to
Apply the Acer advisory update from Community KB 19877 for NitroSense/PredatorSense / System Monitor. If no update is available for your build: disable or uninstall AcerSysHardwareService / NitroSense/PredatorSense per Acer guidance until patched. Treat as local post-compromise LPE on Acer Windows endpoints.

Primary: CVE.org — CVE-2026-50610 Acer System Monitoring improper access control / LPE · Vendor: Acer Community KB 19877 — CVE-2026-50610 advisory (vendor remediation) · CVE: CVE-2026-50610 · Intrinsec — Acer System Monitor named-pipe LPE (CVE-2026-50610) (29 Sep 2026)

vulnerabilities