A high-severity privilege escalation vulnerability tracked as CVE-2023-54353 affects Chromacam 4.0.3.0 through an unquoted Windows service path in PsyFrameGrabberService. The service binary is configured as C:\Program Files (x86)\Personify\ChromaCam\64\PsyFrameGrabberService.exe without quotation marks, while the service starts automatically and runs with LocalSystem privileges. An attacker with existing local access and the ability to write to affected directories can abuse Windows path parsing to place a malicious executable and have it launched with elevated rights when the service starts.
Public exploit details published on Exploit-DB describe planting files such as Program.exe or a rogue PsyFrameGrabberService.exe in writable locations including C:\ or parts of C:\Program Files (x86)\Personify\. The issue is rated 8.5 under CVSS 4.0 and 7.8 under CVSS 3.1, and is described as not remotely exploitable because it requires local write access. Recommended remediation is to properly quote the PsyFrameGrabberService path and verify the service configuration after the change.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry for CVE-2023-54353 documented the Chromacam 4.0.3.0 unquoted service path privilege escalation flaw, including CVSS 4.0 and 3.1 scores and remediation guidance to properly quote the PsyFrameGrabberService path. The entry identifies VulnCheck as the source and notes the issue is a local, not remote, privilege escalation vulnerability.
Exploit-DB published EDB-ID 51210 describing a local privilege escalation issue in Chromacam 4.0.3.0 caused by an unquoted service path in the PsyFrameGrabberService Windows service. The report states the service runs as LocalSystem and could allow code execution if a local attacker can place a malicious executable in a writable path segment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.