SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6116

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

HIGH 7.8EPSS 41.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 41.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
41.59% probability · 99th percentile
CISA KEV
Not listed
Affected
artifex/ghostscript · fedoraproject/fedora · canonical/ubuntu linux · debian/debian linux · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.