Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
References
Configurations
No configuration.
History
19 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 15:16
Updated : 2026-06-23 15:42
NVD link : CVE-2023-54353
Mitre link : CVE-2023-54353
CVE.ORG link : CVE-2023-54353
JSON object : View
Products Affected
No product.
CWE
CWE-428
Unquoted Search Path or Element
