PT-2026-97239 · Artifex · Ghostscript

·

CVE-2026-19547

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Ghostscript for Windows versions prior to 10.08.0
Description Ghostscript for Windows allows local privilege escalation via PostScript resource file hijacking. The application searches for resource files in predictable paths under C:gs that are not created by default. Because Windows default Access Control Lists (ACLs) allow authenticated users to create directories at the root of C:, a local attacker can create the required directory structure and place a malicious PostScript file. When Ghostscript is executed by any user or service, this file is automatically loaded and executed with the privileges of the Ghostscript process, leading to arbitrary code execution and full compromise of the process context.
Recommendations Update Ghostscript for Windows to version 10.08.0.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19547

Affected Products

Ghostscript