PT-2026-97239 · Artifex · Ghostscript
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Ghostscript for Windows versions prior to 10.08.0
Description
Ghostscript for Windows allows local privilege escalation via PostScript resource file hijacking. The application searches for resource files in predictable paths under
C:gs that are not created by default. Because Windows default Access Control Lists (ACLs) allow authenticated users to create directories at the root of C:, a local attacker can create the required directory structure and place a malicious PostScript file. When Ghostscript is executed by any user or service, this file is automatically loaded and executed with the privileges of the Ghostscript process, leading to arbitrary code execution and full compromise of the process context.Recommendations
Update Ghostscript for Windows to version 10.08.0.
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript