CVE-2018-16509

HIGH EXPLOITED IN THE WILD LAB

Artifex Ghostscript <9.24 - Privilege Escalation

Title source: llm

Description

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/45369
nomisec WORKING POC 58 stars
by farisv · remote-auth
https://github.com/farisv/PIL-RCE-Ghostscript-CVE-2018-16509
nomisec WORKING POC 3 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2018-16509
nomisec WORKING POC 1 stars
by rhpco · poc
https://github.com/rhpco/CVE-2018-16509
nomisec STUB
by cved-sources · poc
https://github.com/cved-sources/cve-2018-16509
metasploit WORKING POC EXCELLENT
by Tavis Ormandy, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/fileformat/ghostscript_failed_restore.rb

Scores

CVSS v3 7.8
EPSS 0.9176
EPSS Percentile 99.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-05-10
InTheWild.io 2024-05-17
Status published
Products (14)
artifex/ghostscript < 9.24
artifex/gpl_ghostscript < 9.26
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 6.0
... and 4 more
Published Sep 05, 2018
Tracked Since Feb 18, 2026