Arcsoft PhotoStudio 6.0.0.172 contains an unquoted...
High severity
Unreviewed
Published
Dec 19, 2025
to the GitHub Advisory Database
•
Updated Dec 19, 2025
Description
Published by the National Vulnerability Database
Dec 19, 2025
Published to the GitHub Advisory Database
Dec 19, 2025
Last updated
Dec 19, 2025
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.
References