PT-2025-52517 · Arcsoft · Arcsoft Photostudio
Msd0Pe
·
Published
2025-12-19
·
Updated
2025-12-20
·
CVE-2023-53946
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Arcsoft PhotoStudio version 6.0.0.172
Description
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability within the ArcSoft Exchange Service. This allows local attackers to potentially escalate privileges. Specifically, attackers can place a malicious executable within an unquoted path, and the service may execute this code with system-level permissions.
Recommendations
Apply appropriate quoting to the service path to prevent the execution of unauthorized executables.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcsoft Photostudio