CVE-2024-29510Patch(artifex / ghostscript)

LOWCVSS 6.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch artifex ghostscript systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghostscript

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ghostscript

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2024-29510 : GHOSTSCRIPT FORMAT STRING INJECTION + SAFER SANDBOX BYPASS RCE ALERT 🚨 Ghostscript A critical unauthenticated remote code execution vulnerability has been disclosed in Ghostscript, allowing attackers to bypass the SAFER sandbox via format string injection, leading to full code execution during document processing. Risk Severity: Critical (Public PoC + high exploit reliability, immediate patching required) Impact: • Full remote code execution (RCE) in Ghostscript process context • Complete SAFER sandbox bypass enabling unrestricted dangerous operator access • Server compromise in document processing pipelines • Potential system takeover when Ghostscript runs with elevated privileges • Exposure of sensitive documents and internal processing queues Root Cause: CWE-134 Use of Externally-Controlled Format String Improper sanitization of format string specifiers in uniprint device parameter handling allows attackers to trigger arbitrary memory corruption. Exploitation occurs before SAFER sandbox enforcement, completely nullifying Ghostscript’s primary security boundary. Attackers can: • Upload malicious PDF or PostScript documents • Inject crafted format string payloads such as %n %s %x • Trigger arbitrary memory read and write • Escape SAFER sandbox • Achieve full remote code execution • Compromise backend document processing servers • Pivot into internal infrastructure Are You Affected? Vulnerable: Ghostscript earlier than 10.03.1 and downstream applications embedding Ghostscript including ImageMagick, LibreOffice, CMS upload pipelines, cloud document services, and print servers Fixed in: Ghostscript 10.03.1 Immediate Actions: Patch Now: Upgrade to Ghostscript 10.03.1 or later immediately Mitigation (if patching is delayed): Disable Ghostscript delegates, restrict PDF and PS processing, isolate document processing servers Audit and Monitor: Review Ghostscript crashes, suspicious uploads, unexpected child processes, and outbound connections Incident Response: If exposed, isolate host, rotate secrets, preserve forensic artifacts, and review all processed documents Given Ghostscript’s massive deployment footprint, this is a high blast radius vulnerability treat exploitation as likely and patch immediately 🛡️ #ostorlabCVE

    Post summary

    The alert announces a critical, unauthenticated RCE in Ghostscript via format string injection with a public PoC; immediate patching to 10.03.1 is required to mitigate the sandbox bypass.

    0000099
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appartifexghostscript---

Explore more