Full Report
Untrusted Search Path vulnerability (CVE-2026-19547) has been found in Ghostscript software.
Analysis Summary
# Vulnerability: Ghostscript Windows Local Privilege Escalation (Untrusted Search Path)
## CVE Details
- **CVE ID**: CVE-2026-19547
- **CVSS Score**: Not explicitly provided in the source (Typically High for LPE; estimated 7.8 based on vector)
- **CWE**: CWE-426 (Untrusted Search Path)
## Affected Systems
- **Products**: Ghostscript for Windows (Artifex Software Inc.)
- **Versions**: All versions prior to **10.08.0**
- **Configurations**: Windows installations where the default root directory (`C:\`) allows authenticated users to create new directories (default Windows behavior).
## Vulnerability Description
Ghostscript for Windows attempts to load PostScript resource files from a specific hardcoded path: `C:\gs\`. By default, this directory does not exist on standard Windows installations.
Because Windows allows any authenticated user to create folders at the root of the `C:` drive, a low-privileged attacker can manually create the `C:\gs\` directory structure and plant a malicious PostScript file. When a higher-privileged user or a system service executes Ghostscript, the application automatically searches for and executes the planted file, leading to arbitrary code execution within the security context of the Ghostscript process.
## Exploitation
- **Status**: Reported and coordinated via CERT Polska; PoC methodology described.
- **Complexity**: Low (requires simple directory creation and file placement).
- **Attack Vector**: Local (Attacker must be an authenticated local user).
## Impact
- **Confidentiality**: High (Full access to process memory and data)
- **Integrity**: High (Ability to modify system files and configurations)
- **Availability**: High (Ability to crash the process or system)
- **Result**: Full compromise of the Ghostscript process context, potentially leading to full system takeover if Ghostscript is run by an administrator or service account.
## Remediation
### Patches
- **Version 10.08.0**: This version addresses the search path logic to prevent hijacking. Users should upgrade immediately.
### Workarounds
- **Restrict Root Permissions**: Modify the Access Control List (ACL) of the `C:\` drive to prevent non-administrative users from creating new folders.
- **Pre-emptive Directory Creation**: Administrators can manually create the `C:\gs\` directory and set strict permissions (Read/Write only for Administrators/System) to prevent unauthorized users from planting files there.
## Detection
- **Indicators of Compromise**:
- Presence of the directory `C:\gs\` on systems where it was not intentionally created by an administrator.
- Unexpected PostScript (.ps) or resource files within `C:\gs\` or its subdirectories.
- **Detection Methods**: Monitor file system activity for directory creation at the root of the system drive by non-privileged users.
## References
- **Vendor Advisory**: Artifex Software Inc.
- **CERT Polska Advisory**: hxxps[://]cert[.]pl/en/posts/2026/09/CVE-2026-19547/
- **CVE Record**: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-19547
- **CWE-426**: hxxps[://]cwe[.]mitre[.]org/data/definitions/426[.]html