High severity8.4NVD Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2023-53965
CVE-2023-53965
Description
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:o:sound4:big_voice_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:first_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:impact_eco_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:impact_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:ip_connect_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:playout_ula8_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:pulse_eco_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:pulse_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:stream_x2_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:stream_x4_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:stream_x8_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:voice_ula2_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:voice_ula4_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:voice_ula8_firmware:4.1.102:*:*:*:*:*:*:*
- cpe:2.3:o:sound4:wm2_firmware:4.1.102:*:*:*:*:*:*:*
4.1.102+ 1 more
- (no CPE)range: 4.1.102
- (no CPE)range: 4.1.102
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/51167nvdExploitThird Party Advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5721.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/sound-server-service-local-privilege-escalation-via-unquoted-service-pathnvdThird Party Advisory
- web.archive.org/web/20221207074555/https://www.sound4.com/nvdProduct
News mentions
0No linked articles in our index yet.