A high-severity local privilege-escalation vulnerability, CVE-2026-50610, affects Acer's System Monitor engine used by NitroSense and PredatorSense on Windows laptops. Vulnerable AcerSysHardwareService.exe versions 1.0.1018.13 and 1.0.1019.0, associated with the NitroSense 5.1.361 engine, run as LocalSystem while exposing named pipes that authenticated standard users can access without adequate authorization or client impersonation checks.
The service's pipe protocol permits arbitrary registry operations as SYSTEM, including writes under HKLM. A proof of concept registers cmd.exe as the debugger for utilman.exe, allowing an attacker with local standard-user access to obtain a pre-login NT AUTHORITY\SYSTEM shell through Windows accessibility functionality. The issue was privately reported to Acer in May 2026; the available reports do not identify a patch, mitigation, or confirmed exploitation in the wild.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Intrinsec privately reported CVE-2026-50610 to Acer under coordinated disclosure. The flaw affects AcerSysHardwareService.exe, used by NitroSense and PredatorSense, and permits local privilege escalation to NT AUTHORITY\SYSTEM through unauthorized named-pipe registry operations.
A Reddit r/netsec post shared Intrinsec's disclosure of CVE-2026-50610, reporting that a standard Windows user on affected Acer laptops could obtain SYSTEM privileges.
Intrinsec published technical details of high-severity CVE-2026-50610, identifying affected AcerSysHardwareService.exe versions 1.0.1018.13 and 1.0.1019.0. A proof of concept writes an IFEO debugger value for utilman.exe, allowing a local standard user to obtain a pre-login SYSTEM command shell.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.