Record summary

CVE-2023-54353 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.0.3.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBChromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service PathExploitDB exploitby Laguin BenjaminNot analyzed1 file
ExploitDB

PoC details

References

5