CVE-2026-19547 Ghostscript 本地权限提升漏洞
影响本地认证用户可提升权限并以 Ghostscript 进程权限执行任意代码
Ghostscript for Windows 存在 PostScript 资源文件劫持导致的本地权限提升漏洞。程序会在 C:gs 下可预测的路径中查找默认不存在的资源文件,而 Windows 默认 ACL 允许任意认证用户在 C 盘根目录创建目录,攻击者可预先放置恶意 PostScript 文件。当其他用户或服务运行 Ghostscript 时,该文件被自动加载执行。
影响范围
Ghostscript for Windows,官方说明该问题在 10.08.0 版本中修复,具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为本地权限提升(资源文件路径劫持)。成因是 Ghostscript 在 Windows 上从 C:gs 等可预测且默认不存在的路径搜索 PostScript 资源文件,且未校验文件来源与权限。利用方式是攻击者以普通认证用户身份创建对应目录结构并植入恶意 PostScript 文件,待高权限用户或服务调用 Ghostscript 时被自动加载执行。
利用条件与风险
利用前提是攻击者已获得本地认证账户,并能写入 C 盘根目录;实战中可导致权限提升至 Ghostscript 进程权限,风险较高。
修复建议
官方已在 Ghostscript 10.08.0 中修复,建议升级至该版本或更高版本;临时缓解可限制普通用户对 C:gs 及 C 盘根目录的创建权限,并审计相关目录是否存在异常文件。
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\gs\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges.
This issue was fixed in version 10.08.0.