Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup. | |
| Title | Acer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-16T21:28:43.399Z
Reserved: 2026-01-14T17:11:19.899Z
Link: CVE-2021-47825
Updated: 2026-01-16T21:28:36.313Z
Status : Received
Published: 2026-01-16T19:16:07.353
Modified: 2026-01-16T19:16:07.353
Link: CVE-2021-47825
No data.
OpenCVE Enrichment
No data.