Description
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges.


This issue was fixed in version 10.08.0.
Published: 2026-09-29
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges. This issue was fixed in version 10.08.0.
Title Local Privilege Escalation in Ghostscript for Windows
First Time appeared Artifex Software Inc.
Artifex Software Inc. ghostscript
Weaknesses CWE-426
CWE-427
CPEs cpe:2.3:a:artifex_software_inc.:ghostscript:*:*:windows:*:*:*:*:*
Vendors & Products Artifex Software Inc.
Artifex Software Inc. ghostscript
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

threat_severity

Important


Subscriptions

Artifex Software Inc. Ghostscript
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-29T10:52:27.936Z

Reserved: 2026-08-11T14:12:06.293Z

Link: CVE-2026-19547

cve-icon Vulnrichment

Updated: 2026-09-29T10:52:23.686Z

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:11.410

Modified: 2026-09-29T11:16:42.730

Link: CVE-2026-19547

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-29T10:13:31Z

Links: CVE-2026-19547 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:15:08Z

Weaknesses