CVE-2023-34634
Dashboard / Vulnerabilities / CVE-2023-34634
CVE-2023-34634
Published: 1 Aug 2023Last Modified: 12 Aug 2026
Summary:
Details: Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.
References: http://packetstormsecurity.com/files/173825/GreenShot-1.2.10-Arbitrary-Code-Execution.html, http://packetstormsecurity.com/files/174222/Greenshot-1.3.274-Deserialization-Command-Execution.html, https://greenshot.atlassian.net/browse/BUG-3061, https://www.exploit-db.com/exploits/51633, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34634.json, https://nvd.nist.gov/vuln/detail/CVE-2023-34634, https://github.com/greenshot/greenshot/commit/a152e2883fca7f78051b3bd6b1e5cc57355cb44c
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v1.3.274
v1.3.273
v1.3.270
v1.3.265
v1.3.262
v1.3.261
v1.3.260
v1.3.259
v1.3.258
v1.3.256
v1.3.254
v1.3.249
v1.3.246
v1.3.244
v1.3.239
v1.3.238
v1.3.235
v1.3.234
v1.3.231
v1.3.229
v1.3.223
v1.3.220
v1.3.219
v1.3.218
v1.3.213
v1.3.211
v1.3.205
v1.3.204
v1.3.203
v1.3.202
v1.3.201
v1.3.194
v1.3.178
v1.3.157
v1.3.154
v1.3.151
v1.3.108
v1.3.106
v1.3.105
v1.3.76
v1.3.75
v1.3.71
v1.3.69
v1.3.63
v1.3.57
v1.3.55
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
