CVE-2023-34634 is a critical arbitrary code execution vulnerability affecting Greenshot versions 1.2.10 and below, stemming from insecure deserialization of .NET content when a malicious .greenshot file is opened. With a CVSS score of 7.8 (HIGH), it requires user interaction (UI:R) but has low attack complexity (AC:L) and no prior privileges (PR:N), allowing for complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) if exploited. While not on the KEV catalog, public exploit modules exist for Metasploit and ExploitDB, indicating readily available exploit code. Community discussion, though limited, suggests awareness, and its high EPSS score (0.48749) indicates a significant likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.10.6CPE matchmatch criteria | cpe:2.3:a:getgreenshot:greenshot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.