Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges.


This issue was fixed in version 10.08.0.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges. This issue was fixed in version 10.08.0.
Title Local Privilege Escalation in Ghostscript for Windows
First Time appeared Artifex Software Inc.
Artifex Software Inc. ghostscript
Weaknesses CWE-426
CWE-427
CPEs cpe:2.3:a:artifex_software_inc.:ghostscript:*:*:windows:*:*:*:*:*
Vendors & Products Artifex Software Inc.
Artifex Software Inc. ghostscript
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-29T10:52:27.936Z

Reserved: 2026-08-11T14:12:06.293Z

Link: CVE-2026-19547

cve-icon Vulnrichment

Updated: 2026-09-29T10:52:23.686Z

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:11.410

Modified: 2026-09-29T11:16:42.730

Link: CVE-2026-19547

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-29T10:13:31Z

Links: CVE-2026-19547 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses