nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-54353 CVE-2023-54353
HIGH
Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
Record summary
CVE-2023-54353 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromacamBrowse Personifyinc / Chromacam | CVE List | 4.0.3.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBChromacam 4.0.3.0 - PsyFrameGrabberService Unquoted Service PathExploitDB exploitby Laguin BenjaminNot analyzed1 file
References
5Official Product Homepageproduct
https://personifyinc.com/ Product Referenceproduct
https://personifyinc.com/download/chromacam ExploitDB-51210exploit
https://www.exploit-db.com/exploits/51210 VulnCheck Advisory: Chromacam 4.0.3.0 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/chromacam-unquoted-service-path-privilege-escalation