在随 NitroSense 和 PredatorSense 提供的 Acer System Monitoring 组件中发现了一个漏洞,该漏洞源于特权服务中访问控制不足。经过认证的本地用户可能能够访问该服务并执行未经授权的注册表修改,从而导致本地权限提升(privilege escalation)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Acer | System Monitoring | * ~ 1.0.19.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50605 | 7.4 HIGH | Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50609 | 7.4 HIGH | Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50603 | 4.9 MEDIUM | Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorS |
| CVE-2026-50604 | 4.9 MEDIUM | Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50607 | 2.7 LOW | WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50606 | 1.2 LOW | Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and Preda |
| CVE-2026-50608 | 1.2 LOW | Authentication Vulnerability in NitroSense and PredatorSense Software |
No comments yet