CVE-2023-54353 PUBLISHED

Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation

Assigner: VulnCheck
Reserved: 10.01.2026 Published: 19.06.2026 Updated: 19.06.2026

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Personifyinc
Product Chromacam
Versions
  • Version 4.0.3.0 is affected

Credits

  • Laguin Benjamin (MONK-MODE) finder

References

Problem Types

  • Unquoted Search Path or Element CWE