Vulnerability CVE-2023-34634


Published: 2023-08-01

Description:
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.

See advisories in our WLB2 database:
Topic
Author
Date
High
GreenShot 1.2.10 Arbitrary Code Execution
p4r4bellum
31.07.2023

 References:
http://packetstormsecurity.com/files/173825/GreenShot-1.2.10-Arbitrary-Code-Execution.html
https://github.com/greenshot/greenshot/commit/a152e2883fca7f78051b3bd6b1e5cc57355cb44c
https://www.exploit-db.com/exploits/51633
https://greenshot.atlassian.net/browse/BUG-3061

Copyright 2024, cxsecurity.com

 

Back to Top