CVE-2023-54353
Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-428
- Published
- 2026-06-19
- Last modified
- 2026-06-23
Affected products
- Personifyinc Chromacam
Weakness type
Related vulnerabilities
- CVE-2026-77827 — Maono Link local privilege escalation
- CVE-2026-66839 — NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path...
- CVE-2026-18755 — GV-ASManager DLL hijacking vulnerability
- CVE-2026-9128 — Studio 5000 Logix Designer® – Multiple Vulnerabilities
- CVE-2026-8864 — HP Fan Control App – Potential Escalation of Privilege
- CVE-2025-71326 — AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
- CVE-2022-50971 — Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
- CVE-2021-47985 — Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation