CVE-2025-14305

7.8

Acer · ListCheck.exe

A local privilege escalation vulnerability in Acer ListCheck.exe allows authenticated local attackers to replace the executable with a malicious file, resulting in arbitrary code execution as the system.

Executive summary

The Acer ListCheck.exe utility contains a local privilege escalation vulnerability that enables authenticated attackers to execute malicious code with system level privileges.

Vulnerability

The vulnerability stems from incorrect authorization (CWE-863), where a local authenticated attacker can replace the legitimate ListCheck.exe file with a malicious version. Because the system subsequently executes this file, the attacker gains elevated privileges.

Business impact

This vulnerability poses a significant risk to system integrity and security. By successfully exploiting this flaw, a local attacker can move from a standard user account to full system control, potentially compromising sensitive data, installing persistent backdoors, or disabling security software. Given the CVSS score of 7.8, this is classified as a High severity issue that requires immediate attention to prevent unauthorized administrative access.

Remediation

Immediate Action: As the software is no longer maintained, the recommended remediation is to delete the ListCheck.exe program from all systems immediately.

Proactive Monitoring: Security teams should monitor for unauthorized file modifications in directories where legacy tools are stored and review system logs for unexpected execution of binaries.

Compensating Controls: Implement strict file system permissions and host based intrusion detection systems to prevent non-privileged users from modifying or replacing critical executable files.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Because Acer has confirmed that ListCheck.exe is no longer maintained, no security patch will be released for this product. Organizations should prioritize the identification and removal of this utility from all company assets to eliminate the risk of privilege escalation. Failure to remove the software leaves the system permanently susceptible to this local attack vector.

More Acer CVEs

Sources