Netskope Threat Labs

FILE-OTHER Ghostscript PostScript remote code execution attempt

IPS-CFW

1 SID: 49085

Detects a document exploiting CVE-2019-6116, a flaw in Ghostscript's PostScript handling that escapes the interpreter's safety checks and can allow code execution. The rule matches the privileged operators that public exploits use to break out of the sandbox.