CVE-2023-54353 Details
Description
Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
A vulnerability exists in ChromaCam version 4.0.3.0 within the PsyFrameGrabberService, where an unquoted service path allows local attackers to execute arbitrary code. This is achieved by placing malicious executables in directories in the unquoted path. When the service starts automatically at boot, these executables are executed with LocalSystem privileges. The vulnerability affects users with write access to the C: drive or specific subdirectories, such as 'C:\Program Files (x86)\Personify\'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://personifyinc.com/ | [email protected] | Vendor |
| https://personifyinc.com/download/chromacam | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/51210 | [email protected] | Broken LinkExploit |
| https://www.vulncheck.com/advisories/chromacam-unquoted-service-path-privilege-escalation | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Personify Chromacam | <= 4.0.3.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |
Volerion