Acer components running as LocalSystem on a fresh machine (each a candidate target; only one shown exploitable): Roughly a dozen (Source: Intrinsec research (October 1, 2026))
The risk sits in software that came in the box
Many laptops ship with a vendor "control center" that tunes fans, switches performance modes and lights the keyboard. Acer ships two such tools, NitroSense and PredatorSense. Both rely on the same underlying component, named Acer System Monitor. Researchers at Intrinsec, a French security firm, found that this component lets any standard user take full control of the machine. The flaw is tracked as CVE-2026-50610.
One caveat first. Intrinsec says these Acer tools are not widespread on company devices. So this is not a claim about every corporate laptop.
The wider lesson is about where to look. A laptop's attack surface includes the software that came in the box. Vendor utilities like this can easily be missed from a procurement list, and teams should check whether they are on yours. Yet this one runs with the most powerful account on Windows.
How the flaw works
The product is split in two. One part is an app that runs with the user's ordinary rights. The other is a background service running as LocalSystem, which Intrinsec calls the most powerful account on Windows. Reading hardware sensors needs high rights, so the split is sound design.
The two halves talk through a named pipe. That is a channel that lets one program send messages to another. The weakness is this bridge between a low-rights world and a high-rights one.
The researchers decoded the pipe's security settings. Any account that can sign in to the machine may connect and send commands, whatever its rights. On its own, that is not a flaw. Many programs open their pipes widely and then check each caller themselves.
This service did not check. The researchers looked for the Windows functions a server uses to take on a caller's rights or test them. None were imported, and none appeared as strings in the binary. So every command that arrives runs under the service's own SYSTEM identity.
Think of a bank teller window that passes every note to the vault without asking who wrote it. The window being open is normal. The vault trusting everything that comes through is the problem.
From one message to full control
The service's message parser accepts numbered commands. Beside the hardware reads sit generic registry operations. The registry is the settings database Windows uses to decide how the machine behaves.
Intrinsec showed that command 3 lets a caller create and write registry keys. A standard user sent one message. A SYSTEM process then wrote a machine-wide key, on behalf of an account with no rights to that part of the registry.
A registry write is not code execution by itself. Intrinsec's proof of concept used it to register a "debugger" for utilman, the accessibility feature reachable from the Windows login screen. Windows then launches the attacker's chosen program, cmd.exe, in its place. Clicking the accessibility button gave a SYSTEM shell.
The researchers name two other routes from the same primitive: rewriting a service's launch command, and redirecting a COM object to a DLL the attacker controls. That suggests the root problem is the missing check on callers, not any one route.
What this does and does not mean
Some limits matter. The attacker needs a local standard account first. Intrinsec presents a proof of concept, and its write-up does not report attacks in the wild.
Our view is that flaws like this matter in the second step of an intrusion. Once someone holds an ordinary account, through a shared login or a stolen password, an escalation flaw removes the next barrier. Intrinsec points defenders to guidance on Acer's website. Its write-up does not detail a fix.
Questions to put to your team
Do we know which laptops run NitroSense, PredatorSense or Acer System Monitor, and which engine version each has? Has someone read Acer's guidance and recorded a decision?
Does our device inventory list vendor utilities, or only the software we deployed ourselves? Who owns updates for it?
Which staff share machines or hold only standard accounts on laptops with vendor tools? Those are the people this flaw would matter to.
A pipe open to everyone is common. What deserves an audit is the service behind it that trusts every caller.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: intrinsec.com.





