


Perceptive Security
SOC/SIEM Consultancy

Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbiā¦
Published:
15 januari 2026 om 23:00:00
Alert date:
16 januari 2026 om 20:08:27
Source:
nvd.nist.gov
Operating Systems, Enterprise Applications
CVE-2021-47826 affects Acer Backup Manager version 3.0.0.99 with an unquoted service path vulnerability in the NTI IScheduleSvc service. The vulnerability allows local users to potentially execute arbitrary code by exploiting the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\. Attackers can inject malicious executables that would run with elevated LocalSystem privileges. This is a local privilege escalation vulnerability that requires local access to exploit. The vulnerability has been publicly disclosed with exploit code available.
Technical details
Mitigation steps:
Affected products:
Acer Backup Manager
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2021-47826
https://www.acer.com/ac/en/US/content/home
https://www.exploit-db.com/exploits/49889
https://www.vulncheck.com/advisories/acer-backup-manager-module-ischedulesvcexe-unquoted-service-path
Related CVE's:
Related threat actors:
IOC's:
C:\Program Files (x86)\NTI\Acer Backup Manager\
This article was created with the assistance of AI technology by Perceptive.
