Local Privilege Escalation Vulnerability in Ghostscript for Windows
CVE-2026-19547
What is CVE-2026-19547?
Ghostscript for Windows is susceptible to a local privilege escalation vulnerability due to improper handling of PostScript resource file paths. The application searches for these resources in predictable locations under C:\gs, which are not present in standard Windows installations. Given that Windows default ACLs permit any authenticated user to create directories at the root of C:, an attacker can craft the necessary directory structure and insert a malicious PostScript file. When Ghostscript is launched by any user or service, this file will be executed with the process's full privileges, potentially leading to a complete compromise of the Ghostscript context and allowing arbitrary code execution on the system.
Affected Version(s)
Ghostscript Windows 0 < 10.08.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
