VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2023-54353

CVE-2023-54353: Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attack

Published Jun 19, 2026 CVSS 8.5

Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.

Affected AI Products

chroma
Get the weekly digest. Every Monday: top AI security stories of the week. Free.