{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9489", "assignerOrgId": "8fc372e3-d9c5-46e4-9410-38469745c639", "state": "PUBLISHED", "assignerShortName": "Acer", "dateReserved": "2026-05-25T01:34:16.727Z", "datePublished": "2026-05-25T01:50:32.063Z", "dateUpdated": "2026-05-26T15:20:21.624Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "8fc372e3-d9c5-46e4-9410-38469745c639", "shortName": "Acer", "dateUpdated": "2026-05-25T01:50:32.063Z" }, "title": "NitroSense V3: Local Privilege Escalation (LPE) vulnerability", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-22", "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-269", "description": "CWE-269: Improper Privilege Management", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-284", "description": "CWE-284: Improper Access Control", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-732", "description": "CWE-732: Incorrect Permission Assignment for Critical Resource", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-69", "descriptions": [ { "lang": "en", "value": "CAPEC-69 Target Programs with Elevated Privileges" } ] } ], "affected": [ { "vendor": "Acer", "product": "NitrorSense V3", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "3.01.3001", "lessThanOrEqual": "3.01.3052", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges." } ] } ], "references": [ { "url": "https://community.acer.com/en/kb/articles/19652" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "LOCAL", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 8.5, "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } } ], "solutions": [ { "lang": "en", "value": "Please update for versionĀ \n3.01.3056.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Please update for version \n3.01.3056." } ] } ], "credits": [ { "lang": "en", "value": "Artem Domarev", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-26T15:11:04.376350Z", "id": "CVE-2026-9489", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-26T15:20:21.624Z" } } ] } }