PT-2026-38677 · Acer · Predatorsense
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PredatorSense versions 3.00.3136 through 3.00.3196
Description
Local Privilege Escalation (LPE) occurs because the program exposes a Windows Named Pipe—a mechanism for inter-process communication—that uses a custom protocol to invoke internal functions. Due to a misconfiguration of this Named Pipe, any authenticated local user can execute arbitrary code and delete arbitrary files with NT AUTHORITYSYSTEM privileges, allowing for full system compromise with elevated privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Access Control
Incorrect Permission
Path traversal
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Predatorsense