CVE-2026-25792 is a medium-severity binary hijacking vulnerability (CWE-426) affecting Greenshot versions 1.3.312 and below. A local attacker with high privileges can achieve arbitrary code execution by placing a malicious executable in a specific search path. This occurs when a user double-clicks the application's tray icon, which attempts to launch explorer.exe without an absolute path. The vulnerability carries a CVSS score of 6.5, indicating high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.312CPE matchmatch criteria | cpe:2.3:a:getgreenshot:greenshot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.