Vulnerability Description
Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://personifyinc.com/
- https://personifyinc.com/download/chromacam
- https://www.exploit-db.com/exploits/51210
- https://www.vulncheck.com/advisories/chromacam-unquoted-service-path-privilege-e
FAQ
What is CVE-2023-54353?
CVE-2023-54353 is a vulnerability with a CVSS score of 7.8 (HIGH). Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path ...
How severe is CVE-2023-54353?
CVE-2023-54353 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-54353?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.