Greenshot.NET.CVE-2023-34634.Insecure.Deserialization
Description
This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in Greenshot.
The vulnerability is due to insecure deserialization when handling an crafted .greenshot file. A remote attacker could exploit the vulnerability by tricking an user to open the crafted .greenshot file in a vulnerable system. Successful exploitation can result in arbitrary code execution on the target server, in the worst case, under the security context of SYSTEM.
Affected Products
Greenshot version 1.2.10 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/greenshot/greenshot/commit/a152e2883fca7f78051b3bd6b1e5cc57355cb44c
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |