logo

RCE bug in widely used Ghostscript library now exploited in attacks

ID: b0ed0894-312d-5032-a664-aa471c597d91

STIX ID: report--b0ed0894-312d-5032-a664-aa471c597d91

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-07-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical Ghostscript format-string vulnerability (CVE-2024-29510) affecting Ghostscript 10.03.0 and earlier enables sandbox escape and remote code execution; researchers released a technical write-up, PoC and a testkit, and active exploitation has been observed using EPS files disguised as images—users should upgrade to Ghostscript v10.03.1 or apply vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.