Skip to content
Threat Feed
high advisory

Ghostscript Local Privilege Escalation Vulnerability

A vulnerability in the Ghostscript interpreter allows a local attacker to escalate privileges by processing specifically crafted documents.

A security vulnerability exists in the Ghostscript interpreter that permits a local attacker to perform privilege escalation. The issue stems from insufficient security constraints within the interpreter, which can be bypassed when the software processes malicious documents or input files. This vulnerability poses a significant risk to systems that use Ghostscript to perform automated document conversion or processing, such as web servers or document management systems that handle untrusted user-submitted files. Attackers can leverage this flaw to gain elevated permissions on the host system, potentially leading to unauthorized access, code execution, or data manipulation. Defensive teams should prioritize auditing systems where Ghostscript is invoked by applications processing external user input.

Impact

Successful exploitation of this vulnerability allows a local attacker to escalate their privileges to those of the user running the Ghostscript process. In enterprise environments, this often results in full system compromise if the service is running with high privileges. Impacted sectors include any organization relying on Ghostscript for document processing, particularly in Linux, Windows, or macOS environments where the interpreter is integrated into administrative or web-facing workflows.

Recommendation

Prioritize patching Ghostscript across all affected environments as updates become available from Artifex Software or the relevant OS package maintainer. Given the local nature of the vulnerability, monitor system logs for unusual process execution chains involving 'gs' or 'gswin64c' spawned by web server or document service accounts.


Immediate actions

Inventory all servers and workstations running Ghostscript for version management.

IT Operations 48h

Threat Hunt

Identify applications spawning Ghostscript processes (gs, gswin64c) that receive external input.

T1068 medium medium confidence hunt now

Data: Process creation telemetry

Mitigations

Upgrade Ghostscript to the latest vendor-supplied version.

immediate IT Operations

Ghostscript local privilege escalation

Gaps

  • Lack of specific exploit indicators.