CVE-2026-9489
概要

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.

公表日 2026年5月25日11:16
登録日 2026年5月27日4:07
最終更新日 2026年5月25日11:16
関連情報、対策とツール
共通脆弱性一覧