PT-2026-97206 · Acer · Nitrosense
CVSS v4.0
6.1
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Acer NitroSense versions prior to 5.2.64
Description
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed on localhost TCP port 9993. This occurs because Chromium remote debugging is enabled within the production application, allowing the attacker to execute JavaScript in the privileged application context and achieve arbitrary code execution.
Recommendations
Update Acer NitroSense to a version newer than 5.2.63.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nitrosense