CVE-2023-34634: Critical severity greenshot vulnerability
Published Jul 28, 2023
·Updated
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.
Credit
p4r4bellum
Affected Software
2 affected components
Greenshot Greenshot<=1.2.10
Getgreenshot Greenshot<=1.2.10.6
Remediation
Event History
Jul 28, 2023
Exploit Published
12:00 AM
Known Exploited
12:00 AM
Aug 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34634?
CVE-2023-34634 is rated as critical due to its potential for arbitrary code execution.
2
How do I fix CVE-2023-34634?
To fix CVE-2023-34634, upgrade Greenshot to version 1.2.11 or later where the vulnerability has been addressed.
3
Who is affected by CVE-2023-34634?
Any user of Greenshot versions 1.2.10 and below is affected by CVE-2023-34634.
4
What type of vulnerability is CVE-2023-34634?
CVE-2023-34634 is an arbitrary code execution vulnerability due to insecure deserialization in .NET.
5
What can attackers do with CVE-2023-34634?
Attackers can execute arbitrary code on a vulnerable system by tricking users into opening a malicious .greenshot file.