CVE-2023-53946: Arcsoft Photostudio

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.

Affected products

  • Arcsoft Photostudio: up to and including 6.0.0.172

Published 2025-12-19. Last modified 2026-06-17.