# Ghostscript Windows LPE via file hijacking patched

Published: 2026-09-29 · Severity: routine
Canonical: https://vorant.io/reports/4b7a4fa1-32b5-579f-80f5-78b24d336777/ghostscript-windows-lpe-via-file-hijacking-patched

> Ghostscript for Windows before 10.08.0 lets local users hijack predictable PostScript resource paths under C:\gs\ to escalate privileges.

CERT Polska coordinated disclosure of CVE-2026-19547, a local privilege escalation vulnerability in Ghostscript for Windows. The flaw stems from Ghostscript searching for PostScript resource files in predictable, non-default paths under C:\gs\. Because Windows' default ACLs allow any authenticated local user to create directories at the root of C:\, an attacker can pre-create the expected directory structure and plant a malicious PostScript file before Ghostscript is ever run legitimately.

When any user or service subsequently invokes Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process — resulting in arbitrary code execution and full compromise of that process context. This is a classic file/path hijacking privilege escalation issue rather than a remote exploitation vector; it requires local authenticated access to the target machine. The vulnerability was reported by Julian Horoszkiewicz of Atos Threat Research Center and fixed in Ghostscript version 10.08.0.

Defenders running Ghostscript on Windows, particularly in shared or multi-user environments, in print servers, or in any automated pipeline invoking Ghostscript with elevated privileges, should upgrade to 10.08.0 or later. As mitigation prior to patching, restrict write access to the root of C:\ and audit for unexpected directories/files under C:\gs\.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19547

## Detection guidance (public sample)

### Ghostscript Invocation with Suspicious Resource Path

ATT&CK: T1574.001

Detects Ghostscript process execution (gswin32c.exe, gswin64c.exe) originating from non-standard parent processes or with command-line flags that may trigger resource loading from attacker-controlled directories. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Ghostscript Invocation with Suspicious Resource Path
description: Detects Ghostscript processes spawned by non-typical parents (user shells,
  remote execution tools) that may load hijacked PostScript resources from C:\gs\.
  Targets the distinctive Ghostscript binary names and execution context anomalies.
tags:
- attack.privilege-escalation
- attack.t1574.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_ghostscript:
    Image|endswith:
    - \gswin32c.exe
    - \gswin64c.exe
    - \gswin32.exe
    - \gswin64.exe
  selection_suspicious_parent:
    ParentImage|endswith:
    - \cmd.exe
    - \powershell.exe
    - \wmic.exe
    - \rundll32.exe
    - \cscript.exe
  filter_print_service:
    ParentImage|endswith:
    - \spoolsv.exe
    - \svchost.exe
  condition: selection_ghostscript and selection_suspicious_parent and not filter_print_service
falsepositives:
- System administrators manually invoking Ghostscript from command-line for testing
- Legitimate automation scripts launching Ghostscript from batch/PowerShell
level: medium
id: 9efb1e93-edf5-5998-a3c7-291ce275fad9
status: experimental
author: Vorant
references:
- https://cert.pl/en/posts/2026/09/CVE-2026-19547
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-19547

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4b7a4fa1-32b5-579f-80f5-78b24d336777/ghostscript-windows-lpe-via-file-hijacking-patched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
