Windows 版本的 Ghostscript 存在一个通过 PostScript 资源文件劫持实现的本地权限提升漏洞。由于该应用会在 Windows 默认安装环境中不存在的、可预测的 C:\gs\ 路径下搜索 PostScript 资源文件,而 Windows 默认 ACL(访问控制列表)允许任何经过身份验证的用户在 C:\ 根目录下创建目录,因此,经过身份验证的本地攻击者可以创建预期的目录结构并植入恶意的 PostScript 文件。当任何用户或服务随后运行 Ghostscript 时,植入的文件会被自动加载,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Artifex Software Inc. | Ghostscript | 0 ~ 10.08.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet