Skip to content
COOEY

EXPOSURES › CVE-2017-8291

CVE-2017-8291

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-8291 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Artifex Ghostscript allowed remote command execution via a type confusion vulnerability in .rsdparams files.

A type confusion flaw in Ghostscript's .rsdparams handling bypassed -dSAFER and enabled remote code execution. DIBs must ensure Ghostscript is patched and restricted, as unpatched versions remain actively exploited in the wild.

Shame score — A known, actively exploited vulnerability in a widely used PDF processing tool that allowed remote code execution, indicating severe negligence in patch management and security hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.