RCE bug in widely used Ghostscript library now exploited in attacks
ID: b0ed0894-312d-5032-a664-aa471c597d91
STIX ID: report--b0ed0894-312d-5032-a664-aa471c597d91
Feed Name: Bleeping Computer
Threat Score
A critical Ghostscript format-string vulnerability (CVE-2024-29510) affecting Ghostscript 10.03.0 and earlier enables sandbox escape and remote code execution; researchers released a technical write-up, PoC and a testkit, and active exploitation has been observed using EPS files disguised as images—users should upgrade to Ghostscript v10.03.1 or apply vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
