CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write

CVE-2026-50610 (TL-2026-2786) is a high-severity software vulnerability scored CVSS 7.4, first published 2026-09-29. It has no confirmed attribution, affects Acer System Monitor (AcerSysHardwareService.exe), references 1 CVE (CVE-2026-50610), maps to 5 MITRE ATT&CK techniques (T1059.003, T1112, T1546.012), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2786

Threat ID
TL-2026-2786
Severity
HIGH
CVSS
7.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, consumer, enterprise endpoints
Target regions
Global
Detection rules
9
Indicators of compromise
12

AcerSysHardwareService.exe, the Acer System Monitor hardware service bundled with NitroSense and PredatorSense, exposes a SYSTEM-level named pipe to all authenticated users with no caller authentication and generic registry write commands. A standard local user can write arbitrary HKLM values and obtain a SYSTEM shell; Intrinsec published a working IFEO proof of concept on 2026-09-29. No in-the-wild exploitation or attribution has been reported.

How CVE-2026-50610 works

CVE-2026-50610 is a local privilege escalation in Acer's System Monitoring component (AcerSysHardwareService.exe), shipped with NitroSense and PredatorSense. Intrinsec's analysis identifies versions 1.0.1018.13 and 1.0.1019.0 of the service and the NitroSense 5.1.361 engine as affected, and states that PredatorSense shares the same codebase. The CVE record describes insufficient access controls in a privileged service that let an authenticated local user perform unauthorized registry modifications.

Root cause, per Intrinsec: the service listens on two named pipes, systemmonitoring_hardware_service_ (primary target) and predatorsense_hardware_service_, enumerated with AccessChk. Both grant read/write access to NT AUTHORITY\Authenticated Users (SDDL ACE granting GRGWGX to AU). The service does not import or use ImpersonateNamedPipeClient, RevertToSelf, SetThreadToken, AccessCheck or CheckTokenMembership, so it never authenticates or authorizes the caller. The message processor (treadstone::TsClientCommandProcessor::process_pipe) exposes generic registry operations to any pipe client.

Protocol: each message is a uint16 command ID, a uint8 field count, then fields each encoded as uint32 length plus data. Commands: 1 RegCreateKey, 2 RegOpenKey+RegDeleteKey, 3 RegCreateKey+RegSetValue (arbitrary registry value write), 4 RegDeleteValue, 5 RegOpenKey+RegQueryValue. The cmd=3 packet carries the full registry path (HKEY_LOCAL_MACHINE\...) as UTF-16LE, the value name, the REG_* type (4 bytes) and the raw data. Because the service runs as SYSTEM, writes land in protected HKLM locations.

Proof of concept: a standard user sends a cmd=3 packet to the systemmonitoring_hardware_service_ pipe, causing the service to create HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe with a Debugger value of cmd.exe. Invoking the Ease of Access (Utilman) button on the Windows login screen then launches cmd.exe as SYSTEM before authentication. sethc.exe and osk.exe are cited as alternative IFEO targets. The article also notes the registry-write primitive can be converted to SYSTEM code execution via service ImagePath hijacking or COM object repointing.

Disclosure: reported privately to Acer under coordinated disclosure in May 2026; the CVE record was published 2026-09-17 (Rapid7 database) with a CVSS 4.0 base score of 7.4 (HIGH); Intrinsec published full technical details and the PoC on 2026-09-29. A fixed version is not stated in the sources retrieved; Acer guidance is referenced at community.acer.com KB 19877 (not retrievable, HTTP 403). No in-the-wild exploitation, threat actor, or file hashes are reported. Intrinsec classifies the flaw as Improper Access Control (CWE-284); Rapid7 lists no CWE. Rapid7 records an EPSS score of 0% (1st percentile) and the CVE is not in the CISA KEV catalog. The pipe security descriptor is D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU).

MITRE ATT&CK techniques used in TL-2026-2786

Execution

T1059.003 Windows Command Shell

defense-impairment

T1112 Modify Registry

Privilege Escalation

T1546.012 Image File Execution Options Injection

Persistence

T1546.012 Image File Execution Options Injection; T1546.015 Component Object Model Hijacking

stealth

T1574.011 Services Registry Permissions Weakness

Affected products and versions in CVE-2026-50610

  • Acer — System Monitor (AcerSysHardwareService.exe)
    Vulnerable versions: 1.0.1018.13; 1.0.1019.0
  • Acer — NitroSense
    Vulnerable versions: 5.1.361
  • Acer — PredatorSense
    Vulnerable versions: versions bundling the affected Acer System Monitor component

Remediation for CVE-2026-50610

Patches

  • Fixed version not stated in the retrieved sources; consult Acer's advisory (KB 19877)

Immediate actions

  • Follow Acer's guidance (community.acer.com KB 19877) and update NitroSense/PredatorSense and the Acer System Monitor component to the vendor-provided fixed release
  • Inventory endpoints running AcerSysHardwareService.exe (1.0.1018.13 / 1.0.1019.0) and NitroSense 5.1.361 or PredatorSense
  • Hunt for Image File Execution Options Debugger values on utilman.exe, sethc.exe and osk.exe

Workarounds

  • Uninstall NitroSense/PredatorSense or disable the Acer System Monitor hardware service where it is not needed, pending a vendor fix
  • Restrict IFEO registry key modification and monitor for changes with EDR

Longer-term hardening

  • Alert on registry writes under HKLM IFEO, service ImagePath and COM registration keys made by AcerSysHardwareService.exe
  • Remove OEM utilities that are not required on managed fleets
  • Audit OEM services for named pipes whose ACLs grant access to Authenticated Users

CVEs associated with CVE-2026-50610

CVE-2026-50610

Weaknesses (CWE) in CVE-2026-50610

CWE-284

Timeline of CVE-2026-50610

  • Vulnerability reported privately to Acer under coordinated disclosure (Intrinsec states 'May 2026'; exact day not given)
  • CVE-2026-50610 record published: insufficient access controls in Acer System Monitoring service (NitroSense/PredatorSense) allow unauthorized registry modification; CVSS 4.0 base 7.4 HIGH
  • No in-the-wild exploitation, actor attribution, or file IOCs stated in the disclosure; fixed version not stated in retrieved sources
  • Rapid7 records EPSS 0% (1st percentile) and no CISA KEV listing for CVE-2026-50610 at time of research
  • Intrinsec's disclosure points to Acer's published guidance (community.acer.com KB 19877); the guidance page could not be retrieved and no fixed version is stated
  • Working PoC described: cmd=3 registry write sets IFEO Debugger=cmd.exe on utilman.exe, yielding a SYSTEM shell from the Windows login screen
  • Intrinsec publishes full technical analysis: pipe systemmonitoring_hardware_service_ lacks caller authentication and exposes generic registry write commands

Sources cited for CVE-2026-50610

More in vulnerability

Detection coverage for TL-2026-2786

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2786 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats