Description

Acer has rolled out a crucial security update to resolve a newly discovered local privilege escalation vulnerability in its ControlCenter utility. This flaw, officially designated as CVE-2025-5491, has been assigned a CVSS score of 8.8 (High) due to its potential to grant remote, unauthenticated attackers SYSTEM-level access on Windows devices. The problem originates from ACCSvc.exe, a background service integrated into Acer ControlCenter. This service leverages a Windows Named Pipe—a mechanism for inter-process communication (IPC)—that is configured to allow certain system functions to be invoked remotely. However, due to a critical misconfiguration, remote users can interact with this pipe without authentication, significantly increasing the risk of exploitation. One of the functionalities exposed by this service allows the execution of arbitrary executables with NT AUTHORITY\SYSTEM privileges—the highest permission level on Windows. By exploiting the unauthenticated remote access, attackers could use this feature to run malicious code, gain full system control, and execute commands with elevated privileges. ? Acer has acted swiftly to mitigate the vulnerability, releasing ControlCenter version 4.00.3058, which corrects the Named Pipe misconfiguration and enhances overall security controls. This update restricts unauthorized remote access and ensures stronger privilege management.