Arcsoft PhotoStudio Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Arcsoft PhotoStudio versions through 6.0.0.172. The issue arises from an unquoted service path in the ArcSoft Exchange Service, allowing local attackers to place a malicious executable in the unquoted path. When the service is triggered, the executable is executed with system-level permissions, enabling arbitrary code execution.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation to the system level, where an attacker could execute arbitrary code with full administrative rights.

Reproduction

The vulnerability can be reproduced by first identifying the unquoted service path using the Windows Management Instrumentation Command-line (WMIC) tool. After locating the service, a reverse shell payload can be created using Metasploit's msfvenom, and then uploaded to the unquoted path. Once the payload is in place, the service can be restarted, triggering the execution of the malicious payload with system privileges.

Added: Dec 19, 2025, 9:28 PM
Updated: Dec 19, 2025, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.