CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write
CVE-2026-50610 (TL-2026-2786) is a high-severity software vulnerability scored CVSS 7.4, first published 2026-09-29. It has no confirmed attribution, affects Acer System Monitor (AcerSysHardwareService.exe), references 1 CVE (CVE-2026-50610), maps to 5 MITRE ATT&CK techniques (T1059.003, T1112, T1546.012), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2786
- Threat ID
- TL-2026-2786
- Severity
- HIGH
- CVSS
- 7.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, consumer, enterprise endpoints
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
AcerSysHardwareService.exe, the Acer System Monitor hardware service bundled with NitroSense and PredatorSense, exposes a SYSTEM-level named pipe to all authenticated users with no caller authentication and generic registry write commands. A standard local user can write arbitrary HKLM values and obtain a SYSTEM shell; Intrinsec published a working IFEO proof of concept on 2026-09-29. No in-the-wild exploitation or attribution has been reported.
How CVE-2026-50610 works
CVE-2026-50610 is a local privilege escalation in Acer's System Monitoring component (AcerSysHardwareService.exe), shipped with NitroSense and PredatorSense. Intrinsec's analysis identifies versions 1.0.1018.13 and 1.0.1019.0 of the service and the NitroSense 5.1.361 engine as affected, and states that PredatorSense shares the same codebase. The CVE record describes insufficient access controls in a privileged service that let an authenticated local user perform unauthorized registry modifications.
Root cause, per Intrinsec: the service listens on two named pipes, systemmonitoring_hardware_service_ (primary target) and predatorsense_hardware_service_, enumerated with AccessChk. Both grant read/write access to NT AUTHORITY\Authenticated Users (SDDL ACE granting GRGWGX to AU). The service does not import or use ImpersonateNamedPipeClient, RevertToSelf, SetThreadToken, AccessCheck or CheckTokenMembership, so it never authenticates or authorizes the caller. The message processor (treadstone::TsClientCommandProcessor::process_pipe) exposes generic registry operations to any pipe client.
Protocol: each message is a uint16 command ID, a uint8 field count, then fields each encoded as uint32 length plus data. Commands: 1 RegCreateKey, 2 RegOpenKey+RegDeleteKey, 3 RegCreateKey+RegSetValue (arbitrary registry value write), 4 RegDeleteValue, 5 RegOpenKey+RegQueryValue. The cmd=3 packet carries the full registry path (HKEY_LOCAL_MACHINE\...) as UTF-16LE, the value name, the REG_* type (4 bytes) and the raw data. Because the service runs as SYSTEM, writes land in protected HKLM locations.
Proof of concept: a standard user sends a cmd=3 packet to the systemmonitoring_hardware_service_ pipe, causing the service to create HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe with a Debugger value of cmd.exe. Invoking the Ease of Access (Utilman) button on the Windows login screen then launches cmd.exe as SYSTEM before authentication. sethc.exe and osk.exe are cited as alternative IFEO targets. The article also notes the registry-write primitive can be converted to SYSTEM code execution via service ImagePath hijacking or COM object repointing.
Disclosure: reported privately to Acer under coordinated disclosure in May 2026; the CVE record was published 2026-09-17 (Rapid7 database) with a CVSS 4.0 base score of 7.4 (HIGH); Intrinsec published full technical details and the PoC on 2026-09-29. A fixed version is not stated in the sources retrieved; Acer guidance is referenced at community.acer.com KB 19877 (not retrievable, HTTP 403). No in-the-wild exploitation, threat actor, or file hashes are reported. Intrinsec classifies the flaw as Improper Access Control (CWE-284); Rapid7 lists no CWE. Rapid7 records an EPSS score of 0% (1st percentile) and the CVE is not in the CISA KEV catalog. The pipe security descriptor is D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU).
MITRE ATT&CK techniques used in TL-2026-2786
Execution
T1059.003 Windows Command Shell
defense-impairment
Privilege Escalation
T1546.012 Image File Execution Options Injection
Persistence
T1546.012 Image File Execution Options Injection; T1546.015 Component Object Model Hijacking
stealth
Affected products and versions in CVE-2026-50610
- Acer — System Monitor (AcerSysHardwareService.exe)
Vulnerable versions: 1.0.1018.13; 1.0.1019.0 - Acer — NitroSense
Vulnerable versions: 5.1.361 - Acer — PredatorSense
Vulnerable versions: versions bundling the affected Acer System Monitor component
Remediation for CVE-2026-50610
Patches
- Fixed version not stated in the retrieved sources; consult Acer's advisory (KB 19877)
Immediate actions
- Follow Acer's guidance (community.acer.com KB 19877) and update NitroSense/PredatorSense and the Acer System Monitor component to the vendor-provided fixed release
- Inventory endpoints running AcerSysHardwareService.exe (1.0.1018.13 / 1.0.1019.0) and NitroSense 5.1.361 or PredatorSense
- Hunt for Image File Execution Options Debugger values on utilman.exe, sethc.exe and osk.exe
Workarounds
- Uninstall NitroSense/PredatorSense or disable the Acer System Monitor hardware service where it is not needed, pending a vendor fix
- Restrict IFEO registry key modification and monitor for changes with EDR
Longer-term hardening
- Alert on registry writes under HKLM IFEO, service ImagePath and COM registration keys made by AcerSysHardwareService.exe
- Remove OEM utilities that are not required on managed fleets
- Audit OEM services for named pipes whose ACLs grant access to Authenticated Users
CVEs associated with CVE-2026-50610
Weaknesses (CWE) in CVE-2026-50610
CWE-284
Timeline of CVE-2026-50610
- Vulnerability reported privately to Acer under coordinated disclosure (Intrinsec states 'May 2026'; exact day not given)
- CVE-2026-50610 record published: insufficient access controls in Acer System Monitoring service (NitroSense/PredatorSense) allow unauthorized registry modification; CVSS 4.0 base 7.4 HIGH
- No in-the-wild exploitation, actor attribution, or file IOCs stated in the disclosure; fixed version not stated in retrieved sources
- Rapid7 records EPSS 0% (1st percentile) and no CISA KEV listing for CVE-2026-50610 at time of research
- Intrinsec's disclosure points to Acer's published guidance (community.acer.com KB 19877); the guidance page could not be retrieved and no fixed version is stated
- Working PoC described: cmd=3 registry write sets IFEO Debugger=cmd.exe on utilman.exe, yielding a SYSTEM shell from the Windows login screen
- Intrinsec publishes full technical analysis: pipe systemmonitoring_hardware_service_ lacks caller authentication and exposes generic registry write commands
Sources cited for CVE-2026-50610
- Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610 (Intrinsec)
- Acer guidance (referenced by Intrinsec)
- Rapid7 vulnerability database: CVE-2026-50610
- NVD: CVE-2026-50610
- MITRE ATT&CK T1546.012 Image File Execution Options Injection
- MITRE ATT&CK T1112 Modify Registry
- MITRE ATT&CK T1068 Exploitation for Privilege Escalation
More in vulnerability
- CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosd
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
Detection coverage for TL-2026-2786
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2786 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.