---
id: CVE-2023-54353
title: >-
  Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the
  PsyFrameGrabberService that allows local attackers to execute arbitrary code
  by placing malicious executables in unquoted path directories
summary: >-
  Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the
  PsyFrameGrabberService that allows local attackers to execute arbitrary code
  by placing malicious executables in unquoted path directories. Attackers with
  write acc…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-06-19'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54353'
references:
  - url: 'https://personifyinc.com/'
    label: disclosure@vulncheck.com
  - url: 'https://personifyinc.com/download/chromacam'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51210'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/chromacam-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.06304
ingestedAt: '2026-09-26T23:39:28.808Z'
---

## Overview

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
