Local Privilege Escalation Vulnerability in Acer QuickAccess by Acer
CVE-2022-24286
7.8HIGH
What is CVE-2022-24286?
A vulnerability exists in Acer QuickAccess that allows a local privilege escalation due to improper user verification in service communication. The affected user process communicates via a named pipe, which grants general user Read and Write capabilities. This flawed design permits a thread to execute a specific command without validating the user's identity, enabling the service to run commands with elevated system privileges, potentially compromising the system's integrity.