ID:9935 - Exploit for OS Command Injection in Ghostscript - CVE-2023-36664
Published: June 7, 2024
Ghostscript
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). A remote attacker can trick the victim to open a specially crafted PDF file and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.