Description
There exists a .NET deserialization vulnerability in Greenshot version 1.3.274 and below. The deserialization allows the execution of commands when a user opens a Greenshot file. The commands execute under the same permissions as the Greenshot service. Typically, is the logged in user.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/fileformat/greenshot/deserialize_cve_2023_34634msf undefined(deserialize_cve_2023_34634) > show actions ...actions...msf undefined(deserialize_cve_2023_34634) > set ACTION < action-name >msf undefined(deserialize_cve_2023_34634) > show options ...show and set options...msf undefined(deserialize_cve_2023_34634) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub