#VU92102 Insecure DLL loading in Ghostscript - CVE-2024-33871

 

#VU92102 Insecure DLL loading in Ghostscript - CVE-2024-33871

Published: June 13, 2024


Vulnerability identifier: #VU92102
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-33871
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Ghostscript
Software vendor:
Artifex Software, Inc.

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the "Driver" parameter for the "opvp"/"oprp" device specifies the name of a dynamic library and allows any library to be loaded. A remote attacker can pass a specially crafted document to the application and execute arbitrary library on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install updates from vendor's website.

External links