Ghostscript Windows LPE via file hijacking patched
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Ghostscript for Windows before 10.08.0 lets local users hijack predictable PostScript resource paths under C:\gs\ to escalate privileges.
CERT Polska coordinated disclosure of CVE-2026-19547, a local privilege escalation vulnerability in Ghostscript for Windows. The flaw stems from Ghostscript searching for PostScript resource files in predictable, non-default paths under C:\gs\. Because Windows' default ACLs allow any authenticated local user to create directories at the root of C:\, an attacker can pre-create the expected directory structure and plant a malicious PostScript file before Ghostscript is ever run legitimately.
When any user or service subsequently invokes Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process — resulting in arbitrary code execution and full compromise of that process context. This is a classic file/path hijacking privilege escalation issue rather than a remote exploitation vector; it requires local authenticated access to the target machine. The vulnerability was reported by Julian Horoszkiewicz of Atos Threat Research Center and fixed in Ghostscript version 10.08.0.
Defenders running Ghostscript on Windows, particularly in shared or multi-user environments, in print servers, or in any automated pipeline invoking Ghostscript with elevated privileges, should upgrade to 10.08.0 or later. As mitigation prior to patching, restrict write access to the root of C:\ and audit for unexpected directories/files under C:\gs\.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-19547
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,271 reports from 154 sources, 2,726 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs