CVE-2026-19547
Received Received - Intake

Ghostscript for Windows Local Privilege Escalation via PostScript Hijacking

Vulnerability report for CVE-2026-19547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: CERT.PL

Description

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges. This issue was fixed in version 10.08.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
artifex ghostscript 10.08.0
artifex ghostscript to 10.08.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Ghostscript searches for PostScript resource files in predictable paths under C:\gs\ that do not exist by default on Windows. An authenticated local user can create these directories and plant a malicious PostScript file. When Ghostscript runs, it loads and executes this file with full privileges, allowing arbitrary code execution on the machine.

Detection Guidance

Check for the existence of the C:\gs\ directory and verify if any unauthorized PostScript files are present. Inspect Ghostscript process execution logs for unexpected file loads from C:\gs\. Use Windows ACL tools to review directory creation permissions at C:\ root.

Impact Analysis

This vulnerability allows an authenticated local attacker to escalate privileges and execute arbitrary code on the machine with Ghostscript process privileges. This could lead to full system compromise, data theft, or installation of malware. Any user or service running Ghostscript is affected if the malicious file is planted.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA compliance. Unauthorized code execution may result in data breaches, loss of confidentiality, or integrity issues, requiring organizations to address the flaw to maintain regulatory compliance.

Mitigation Strategies

Upgrade Ghostscript to version 10.08.0 or later. Remove or restrict write permissions at the C:\ root to prevent unauthorized directory creation. Monitor for suspicious PostScript files in C:\gs\ paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart