CVE-2026-9489: NitroSense V3: Local Privilege Escalation (LPE) vulnerability
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9489?
CVE-2026-9489 has a risk score of 52 indicating a moderate severity level.
How do I fix CVE-2026-9489?
To remediate CVE-2026-9489, upgrade to Acer NitroSense version 3.01.3056 or later.
What type of vulnerability is CVE-2026-9489?
CVE-2026-9489 is classified as a Local Privilege Escalation (LPE) vulnerability.
Who is affected by CVE-2026-9489?
CVE-2026-9489 affects users of Acer NitroSense version 3.x prior to 3.01.3056.
What causes the vulnerability in CVE-2026-9489?
The vulnerability in CVE-2026-9489 is caused by a misconfigured Windows Named Pipe that allows arbitrary code execution by authenticated local users.