CVE-2018-16509
HIGH 9.3EPSS 92.5%
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
- CVSS v3.0
- 7.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 92.50% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2018-09-05
- Updated
- 2024-08-05
Proof-of-concept exploits (7)
- http://seclists.org/oss-sec/2018/q3/142
- AssassinUKG/CVE_2018_165090★ · 2021-06-08
- cved-sources/cve-2018-165090★ · 2021-04-15
- farisv/PIL-RCE-Ghostscript-CVE-2018-1650961★ · 2021-01-06
- knqyf263/CVE-2018-165093★ · 2019-02-01
- rhpco/CVE-2018-165091★ · 2022-11-07
- shelld3v/RCE-python-oneliner-payload32★ · 2021-09-09