Netskope Threat Labs

FILE-OTHER Imagemagick Ghostscript 9.50 remote code execution attempt

IPS-SWG

1 SID: 58185

First seen
June 2024
Last seen
August 2026

Detects an image file exploiting a Ghostscript delegate flaw in ImageMagick that runs PostScript commands outside the safety sandbox. The rule matches the document type declarations that public exploits use to reach the interpreter with shell access.