EXPOSURES › CVE-2017-8291
CVE-2017-8291
HIGH ⌖ ON CISA KEV · EXPLOITEDArtifex Ghostscript allowed remote command execution via a type confusion vulnerability in .rsdparams files.
A type confusion flaw in Ghostscript's .rsdparams handling bypassed -dSAFER and enabled remote code execution. DIBs must ensure Ghostscript is patched and restricted, as unpatched versions remain actively exploited in the wild.
Shame score — A known, actively exploited vulnerability in a widely used PDF processing tool that allowed remote code execution, indicating severe negligence in patch management and security hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.