{"id":232501,"date":"2026-09-29T13:37:52","date_gmt":"2026-09-29T13:37:52","guid":{"rendered":"https:\/\/www.intrinsec.com\/?p=232501"},"modified":"2026-09-29T14:32:02","modified_gmt":"2026-09-29T14:32:02","slug":"cve-2026-50610-elevation-privileges-acer-nitrosense","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/cve-2026-50610-elevation-privileges-acer-nitrosense\/","title":{"rendered":"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610"},"content":{"rendered":"<h2 id=\"h-CVE-2026-50610-privilege-escalation\" class=\"wp-block-heading\">CVE-2026-50610: privilege elevation on Acer devices<\/h2>\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n<p class=\"wp-block-paragraph\">Many laptops ship with vendor \u00abcontrol center\u00bb software that switches performance modes, tunes the fans and lights up the keyboard. On Acer machines that is NitroSense \/ PredatorSense, built on a shared engine called Acer System Monitor. This article walks through how we reverse-engineered that engine and turned it into a reliable local privilege escalation: any standard user on the machine becomes <code>NT AUTHORITY\\SYSTEM<\/code><\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Why OEM \u00abcontrol center\u00bb software matters for privilege escalation<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reading a CPU temperature is generally a privileged operation.<\/strong> Talking to embedded controllers, fan curves and low-level hardware needs more rights than your desktop session has. So the vendor splits the product into two:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>a <strong>user-facing app<\/strong> that runs as <em>you<\/em>, with your ordinary rights;<\/li>\n<li>a <strong>background service<\/strong> running as <code>LocalSystem<\/code>: the most powerful account on Windows.<\/li>\n<\/ul>\n\n<div style=\"margin-bottom: 2px\">\u00a0<\/div>\n\n<p class=\"wp-block-paragraph\">These two halves somehow have to talk, <strong>and that is that bridge between an unprivileged world and a very privileged one that we could exploit to achieve Local Privilege Escalation on Acer laptops.<\/strong><\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Named pipes<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you already know what a <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/ipc\/named-pipes\" target=\"_blank\" rel=\"noopener\">named pipe<\/a> is, skip ahead. Otherwise, here is a short introduction to them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A named pipe is one of the few ways two programs talk to each other, through messaging in a client-server way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three properties make pipes matter for security:<\/p>\n\n\n\n<ol style=\"padding-left:1.2em;margin-top:0.5em\">\n<li><strong>Access control<\/strong>: like a file or folder, every pipe carries an access-control list. Note that many applications listen to pipes that can be accessed by anyone on the system, and still implement access control in their own way in the background to prevent illegitimate operations.<\/li>\n<li><strong>Impersonation<\/strong>: the program behind the pipe runs with <em>its own<\/em> privileges. If it is a SYSTEM service, everything it does in response to your message runs <em>as SYSTEM<\/em>, unless it deliberately impersonates your rights (thus lowering them and limiting impact in case of breach).<\/li>\n<li><strong>No standard format<\/strong>: when it doesn&#039;t use RPC or other widespread communication protocols, the server comes up with its own language and is entirely responsible for parsing it safely and deciding which requests are allowed.<\/li>\n<\/ol>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Mapping the attack surface<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A fresh Acer machine runs roughly a dozen Acer components as <code>LocalSystem<\/code>. Each is a candidate bridge to SYSTEM; but we have to find the ones reachable from an <em>unprivileged<\/em> account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In particular, we look at the <strong>IPC surface<\/strong>, which named pipes are the highest-value slice, because a SYSTEM service listening on one is, by definition, taking input from other processes. We enumerate the pipes a standard user can <em>write<\/em> to with <a href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/accesschk\" target=\"_blank\" rel=\"noopener\">AccessChk<\/a>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>accesschk.exe -acceptula -w \\pipe\\<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Two Acer pipes come back:<\/p>\n\n\n\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th>Pipe<\/th>\n<th>Access for a standard user<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>systemmonitoring_hardware_service_<\/code><\/td>\n<td>RW <code>NT AUTHORITY\\Authenticated Users<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>predatorsense_hardware_service_<\/code><\/td>\n<td>RW <code>NT AUTHORITY\\Authenticated Users<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Tea <code>systemmonitoring<\/code> and <code>predatorsense<\/code> twins hint at a shared codebase reused across products. We picked <code>systemmonitoring_hardware_service_<\/code> as the primary target. A quick handle search in Process Explorer attributes the pipe to <code>AcerSysHardwareService.exe<\/code>, and <code>sc qc<\/code> confirms it runs as SYSTEM.<\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Issue #1: a pipe open to everyone<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We already know <em>dynamically<\/em> that standard users can write to the pipe. Now we ground it in the code. Grepping the binary&#039;s strings for an SDDL pattern turns up the pipe&#039;s security descriptor in clear:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)<\/code><\/pre>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Following the cross-reference to <code>ConvertStringSecurityDescriptorToSecurityDescriptorW<\/code> ties this string to the <code>CreateNamedPipeW<\/code> call. Decoded by hand, the guest list reads:<\/p>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th>Rule<\/th>\n<th>Effect<\/th>\n<th>Who<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>(A;...;GRWGX;;;AU)<\/code><\/td>\n<td><strong>Allow<\/strong> read + write + execute<\/td>\n<td><strong>Authenticated Users<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This line means that <strong>anyone who can log in (privileged or not) may open this pipe and send commands.<\/strong><\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Issue #2: nobody checks who&#039;s calling<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned earlier though, a pipe reachable by everyone is not a vulnerability in itself, as many programs choose to implement specific access control beyond this first gate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A pipe server that intends to honor its callers&#039; privileges would necessarily reference a specific, small set of Win32 functions. So we enumerate the full import table and look for them, eg:<\/p>\n\n\n\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th>Function<\/th>\n<th>Purpose<\/th>\n<th>Here?<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>ImpersonateNamedPipeClient<\/code><\/td>\n<td>adopt the caller&#039;s token<\/td>\n<td><strong>absent<\/strong><\/td>\n<\/tr>\n<tr>\n<td><code>RevertToSelf<\/code><\/td>\n<td>drop impersonation<\/td>\n<td><strong>absent<\/strong><\/td>\n<\/tr>\n<tr>\n<td><code>SetThreadToken<\/code><\/td>\n<td>apply a token to a thread<\/td>\n<td><strong>absent<\/strong><\/td>\n<\/tr>\n<tr>\n<td><code>AccessCheck<\/code><\/td>\n<td>evaluate rights against a descriptor<\/td>\n<td><strong>absent<\/strong><\/td>\n<\/tr>\n<tr>\n<td><code>CheckTokenMembership<\/code><\/td>\n<td>test group\/SID membership<\/td>\n<td><strong>absent<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">None of them are imported, and none of them appear anywhere in the binary as strings either, so they aren&#039;t being resolved dynamically through <code>GetProcAddress<\/code>. There is therefore <strong>no code path<\/strong> by which the service impersonates a client or checks its rights. Every command that arrives on the pipe executes under the service&#039;s own SYSTEM token.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The only access control on the entire chain is the pipe&#039;s guest list, which admits standard users.<\/strong> Everything after this is just deciding what to ask the program to do.<\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Issue #3: the pipe interacts with the whole registry<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">So we can send commands, and they run as SYSTEM. What can we do with that?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Walking backwards from the pipe primitives (<code>CreateNamedPipeW<\/code> -&gt; <code>ConnectNamedPipe<\/code> -&gt; the message-mode <code>ReadFile<\/code> loop) leads to <code>treadstone::TsClientCommandProcessor::process_pipe<\/code>. This is the parser, and its message format falls straight out of the code:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>offset 0: uint16 cmd (command id) offset 2: uint8 nfields (number of fields) offset 3: fields, each: uint32 length (BYTES) +<\/code><\/pre>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Among the hardware-read commands (GPU frequency, fan state, keyboard health) sit a handful of <strong>generic registry operations.<\/strong><\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Dynamic analysis using Procmon<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Each handler is a C++ method that logs its own name: <code>reg_create_key<\/code>, <code>reg_delete_value<\/code>, <code>reg_set_value<\/code>, and so on. The names are quite clear, but the <strong>wiring between the numeric opcode and those methods<\/strong> is not straightforward.<\/p>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We therefore establish the mapping empirically. We point <a href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/procmon\" target=\"_blank\" rel=\"noopener\">Process Monitor<\/a> at the service&#039;s PID, fire each opcode from a minimal pipe client, and read off the <em>observed<\/em> operations:<\/p>\n\n\n\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th><code>cmd<\/code><\/th>\n<th>Operation observed as SYSTEM<\/th>\n<th>Primitive<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td><code>RegCreateKey<\/code><\/td>\n<td>arbitrary key creation<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td><code>RegOpenKey<\/code> + <code>RegDeleteKey<\/code><\/td>\n<td>arbitrary key deletion<\/td>\n<\/tr>\n<tr>\n<td><strong>3<\/strong><\/td>\n<td><code>RegCreateKey<\/code> + <strong><code>RegSetValue<\/code><\/strong><\/td>\n<td><strong>arbitrary value write \u2013 the most critical<\/strong><\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td><code>RegDeleteValue<\/code><\/td>\n<td>arbitrary value deletion<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td><code>RegOpenKey<\/code> + <code>RegQueryValue<\/code><\/td>\n<td>value read<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Zooming in on cmd=3 and speaking the protocol<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">With the opcode confirmed, we decompile the <code>cmd=3<\/code> handler and trace exactly which inputs are attacker-controlled.<\/p>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Tea <code>cmd=3<\/code> packet has four fields:<\/p>\n\n\n\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th>Field<\/th>\n<th>Thrilled<\/th>\n<th>Encoding<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>0<\/td>\n<td>full path <code>HKEY_LOCAL_MACHINE\\SUB\\KEY<\/code><\/td>\n<td>UTF-16LE, trailing NUL included, length in <strong>bytes<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>value name<\/td>\n<td>UTF-16LE + NUL, length in bytes<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td><code>REG_*<\/code> kind<\/td>\n<td>4 bytes<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>data<\/td>\n<td>raw<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Building the packet is just serializing that layout:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import struct def field(b: bytes) -&gt; bytes: return struct.pack(&quot;<I> bytes: return (s + &quot;\\x00&quot;).encode(&quot;utf-16-le&quot;) # UTF-16LE + trailing NUL def build_write(full_path, value_name, reg_type, data): body = field(wstr(full_path)) body += field(wstr(value_name)) body += field(struct.pack(&quot;<\/code><\/pre>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Upon sending that with a standard-user token, Procmon shows that a machine-wide key was created and written by a SYSTEM process, at the request of an account with no rights to <code>HKLM<\/code> at all.<\/strong><\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">From registry write to SYSTEM code execution<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">An arbitrary registry write is not, by itself, code execution, but on Windows it is one of the most reliably convertible primitives there is.<\/p>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A few classic conversions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Image File Execution Options<\/strong>: register a \u00abdebugger\u00bb for a program and it launches instead of the program, in the privileged context that started it.<\/li>\n<li><strong>Service <code>ImagePath<\/code> hijack<\/strong>: every service stores its launch command under <code>HKLM\\SYSTEM\\CurrentControlSet\\Services\\ \\ImagePath<\/code>. Rewrite that for an existing SYSTEM service and, on its next start, <em>your<\/em> command runs as SYSTEM.<\/li>\n<li><strong>COM hijacking<\/strong>: repoint a registered COM object to a DLL you control.<\/li>\n<\/ul>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Our proof of concept takes the first route. As a standard user, he writes a debugger mapped to <code>cmd.exe<\/code> for the well-known <code>utilman<\/code> accessibility feature that can be reached even before logging in to a Windows session.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Below is an example of first a standard user attempting to directly write a debugger for <code>utilman<\/code> (failing as it should), <strong>and then the same user achieving it using CVE-2026-50610:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1473\" height=\"658\" class=\"wp-image-232504\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc.png\" alt=\"Direct reg add denied, then the Debugger value written as SYSTEM through the Acer pipe and confirmed with reg query\" srcset=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc.png 1473w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc-300x134.png 300w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc-1024x457.png 1024w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc-768x343.png 768w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc-18x8.png 18w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-utilman-poc-650x290.png 650w\" sizes=\"(max-width: 1473px) 100vw, 1473px\" \/>\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n<figcaption class=\"wp-element-caption\">The direct <code>reg add<\/code> is denied (access denied); the same <code>Debugger<\/code> value for <code>utilman.exe<\/code> is then written as SYSTEM through the vulnerable pipe, and <code>reg query<\/code> confirms it now points to <code>cmd.exe<\/code>.<\/figcaption>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Then, we simply click on the accessibility feature from the Windows login screen and achieve SYSTEM shell access:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1920\" height=\"1200\" class=\"wp-image-232505\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell.webp\" alt=\"cmd.exe running as NT AUTHORITY SYSTEM launched from the Windows login screen\" srcset=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell.webp 1920w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-300x188.webp 300w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-1024x640.webp 1024w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-768x480.webp 768w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-1536x960.webp 1536w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-18x12.webp 18w, https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/acer-lpe-system-shell-650x406.webp 650w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\n\n\n<div style=\"margin-bottom: 3px\">\u00a0<\/div>\n\n\n<figcaption class=\"wp-element-caption\">Invoking the accessibility feature from the Windows login screen opens a <code>cmd.exe<\/code> running as <code>NT AUTHORITY\\SYSTEM<\/code>, before any user has authenticated.<\/figcaption>\n<\/figure>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Recommendation<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">For users and defenders running NitroSense \/ PredatorSense \/ Acer System Monitor (which, fortunately, is not widespread among company devices), follow the guidelines on <a href=\"https:\/\/community.acer.com\/en\/kb\/articles\/19877-security-advisory-improper-access-control-vulnerability-in-nitrosense-and-predatorsense-software-cve-2026-50610\" target=\"_blank\" rel=\"noopener\">Acer&#039;s website<\/a>.<\/p>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Disclosure<\/h2>\n\n\n\n<div style=\"margin-bottom: 5px\">\u00a0<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This vulnerability was reported privately to Acer in May 2026 under coordinated disclosure.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Impact:<\/strong> Local Privilege Escalation, standard user to <code>NT AUTHORITY\\SYSTEM<\/code> on Windows<\/li>\n<li><strong>Affected:<\/strong> <code>AcerSysHardwareService.exe<\/code> 1.0.1018.13 \/ 1.0.1019.0 (NitroSense 5.1.361 engine)<\/li>\n<li><strong>Severity:<\/strong> High<\/li>\n<\/ul>\n\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>CVE-2026-50610: privilege elevation on Acer devices \u00a0 Many laptops ship with vendor \u00ab\u00a0control center\u00a0\u00bb software [&hellip;]<\/p>\n","protected":false},"author":51,"featured_media":232507,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-232501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-evaluation-securite"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>CVE-2026-50610 : \u00e9l\u00e9vation de privil\u00e8ges sur Acer NitroSense<\/title>\n<meta name=\"description\" content=\"CVE-2026-50610 : une vuln\u00e9rabilit\u00e9 Acer permet \u00e0 un utilisateur standard d\u2019obtenir les privil\u00e8ges SYSTEM sur Windows. En savoir plus..\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/cve-2026-50610-elevation-privileges-acer-nitrosense\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-50610 : une vuln\u00e9rabilit\u00e9 Acer permet \u00e0 un utilisateur standard d\u2019obtenir les privil\u00e8ges SYSTEM sur Windows. En savoir plus..\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/cve-2026-50610-elevation-privileges-acer-nitrosense\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T13:37:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-29T14:32:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1448\" \/>\n\t<meta property=\"og:image:height\" content=\"1086\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Cassius GARAT\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Cassius GARAT\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/\"},\"author\":{\"name\":\"Cassius GARAT\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/9b7fe59e1d71550521fc716181f6de42\"},\"headline\":\"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610\",\"datePublished\":\"2026-09-29T13:37:52+00:00\",\"dateModified\":\"2026-09-29T14:32:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/\"},\"wordCount\":1276,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChatGPT-Image-29-sept.-2026-13_53_06.png\",\"articleSection\":[\"S\u00e9curit\u00e9 offensive &amp; Audit\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/\",\"name\":\"CVE-2026-50610 : \u00e9l\u00e9vation de privil\u00e8ges sur Acer NitroSense\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChatGPT-Image-29-sept.-2026-13_53_06.png\",\"datePublished\":\"2026-09-29T13:37:52+00:00\",\"dateModified\":\"2026-09-29T14:32:02+00:00\",\"description\":\"CVE-2026-50610 : une vuln\u00e9rabilit\u00e9 Acer permet \u00e0 un utilisateur standard d\u2019obtenir les privil\u00e8ges SYSTEM sur Windows. En savoir plus..\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChatGPT-Image-29-sept.-2026-13_53_06.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChatGPT-Image-29-sept.-2026-13_53_06.png\",\"width\":1448,\"height\":1086,\"caption\":\"privilege_escalation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/cve-2026-50610-elevation-privileges-acer-nitrosense\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/9b7fe59e1d71550521fc716181f6de42\",\"name\":\"Cassius GARAT\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g\",\"caption\":\"Cassius GARAT\"},\"sameAs\":[\"https:\\\/\\\/github.com\\\/garatc\"],\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/cassius-garat\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"CVE-2026-50610: Privilege escalation on Acer NitroSense","description":"CVE-2026-50610: An Acer vulnerability allows a standard user to gain SYSTEM privileges on Windows. Learn more...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/cve-2026-50610-elevation-privileges-acer-nitrosense\/","og_locale":"en_US","og_type":"article","og_title":"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610","og_description":"CVE-2026-50610 : une vuln\u00e9rabilit\u00e9 Acer permet \u00e0 un utilisateur standard d\u2019obtenir les privil\u00e8ges SYSTEM sur Windows. En savoir plus..","og_url":"https:\/\/www.intrinsec.com\/en\/cve-2026-50610-elevation-privileges-acer-nitrosense\/","og_site_name":"INTRINSEC","article_published_time":"2026-09-29T13:37:52+00:00","article_modified_time":"2026-09-29T14:32:02+00:00","og_image":[{"width":1448,"height":1086,"url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png","type":"image\/png"}],"author":"Cassius GARAT","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Cassius GARAT","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/"},"author":{"name":"Cassius GARAT","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/9b7fe59e1d71550521fc716181f6de42"},"headline":"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610","datePublished":"2026-09-29T13:37:52+00:00","dateModified":"2026-09-29T14:32:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/"},"wordCount":1276,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png","articleSection":["S\u00e9curit\u00e9 offensive &amp; Audit"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/","url":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/","name":"CVE-2026-50610: Privilege escalation on Acer NitroSense","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png","datePublished":"2026-09-29T13:37:52+00:00","dateModified":"2026-09-29T14:32:02+00:00","description":"CVE-2026-50610: An Acer vulnerability allows a standard user to gain SYSTEM privileges on Windows. Learn more...","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#primaryimage","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2026\/09\/ChatGPT-Image-29-sept.-2026-13_53_06.png","width":1448,"height":1086,"caption":"privilege_escalation"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/cve-2026-50610-elevation-privileges-acer-nitrosense\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/9b7fe59e1d71550521fc716181f6de42","name":"Cassius GARAT","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/00b9201f468ad7ffb27e35e1f0a9212ea99a6439a50abb73facc0705abc1bad5?s=96&d=retro&r=g","caption":"Cassius GARAT"},"sameAs":["https:\/\/github.com\/garatc"],"url":"https:\/\/www.intrinsec.com\/en\/author\/cassius-garat\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/232501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=232501"}],"version-history":[{"count":25,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/232501\/revisions"}],"predecessor-version":[{"id":232568,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/232501\/revisions\/232568"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media\/232507"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=232501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=232501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=232501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}