CVE-2023-34634

HIGH

Greenshot <1.2.10 - Code Injection

Title source: llm
STIX 2.1

Description

Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.

Exploits (3)

exploitdb WORKING POC
by p4r4bellum · powershelllocalwindows
https://www.exploit-db.com/exploits/51633
nomisec WORKING POC 2 stars
by radman404 · poc
https://github.com/radman404/CVE-2023-34634
metasploit WORKING POC EXCELLENT
by p4r4bellum, bwatters-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/greenshot_deserialize_cve_2023_34634.rb

Scores

CVSS v3 7.8
EPSS 0.3803
EPSS Percentile 97.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
getgreenshot/greenshot < 1.2.10.6
Published Aug 01, 2023
Tracked Since Feb 18, 2026