CVE-2026-19547
Last modified
CVE-2026-19547 is a high-severity vulnerability rated 7/10 on the CVSS scale. Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file.
Description
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges. This issue was fixed in version 10.08.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Artifex Software Inc. | Ghostscript | < 10.08.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-19547?
How severe is CVE-2026-19547?
How do I fix CVE-2026-19547?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19535Nozomi Networks Labs identified a CWE-352: Cross-Site Reques…8.6
- CVE-2026-19538The BLOCKED access control list items that are evaluated to …7.5
- CVE-2026-19539Authorization Bypass Through User-Controlled Key in the tick…8.6
- CVE-2026-19542Calling tdelete on a sufficiently deep tree in the GNU C Lib…5.6
- CVE-2026-19543IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2…6.2
- CVE-2026-19546A flaw was found in DBI. This is a fix for a partial fix for…8.8
- CVE-2026-19548Multiple Use-After-Free vulnerabilities were found in the ad…5.5
- CVE-2026-19550A flaw was found in FreeIPA. The trust-fetch-domains command…8.2
- CVE-2026-19556Use after free in V8 in Google Chrome prior to 151.0.7922.13…8.8
- CVE-2026-19557Use after free in TabStrip in Google Chrome on Mac prior to …8.3
- CVE-2026-19558Use after free in Extensions in Google Chrome prior to 151.0…7.5
- CVE-2026-19559Use after free in HTML in Google Chrome prior to 151.0.7922.…8.8
Are you affected by CVE-2026-19547?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
