CVE-2023-53946
Severity CVSS v4.0:
HIGH
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
19/12/2025
Last modified:
19/12/2025
Description
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH



