CVE-2026-9490
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). To mitigate this potential local service disruption, Acer requires users to update the software to the latest version.
- Affected products
- Acer Care Center
- Acer Care Center
- < 4.00.3060
- CVSS 4.0
- 6.8 MEDIUM
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.2% (7th percentile)
- Weakness
- CWE-269
- NVD status
- Analyzed
- Published
- 2026-05-25
- Attack patterns
- CAPEC-610
- Entry point
- message type 0x03 path
- Path
- \\.\pipe\treadstone_service_LightMode
Fix
Please update to v4.00.3060.
CVE-2026-9490 at NVD
2 known exploits for CVE-2026-9490
Proof-of-concept code and exploit modules indexed by Sploitus