Netskope Threat Labs

FILE-IMAGE Greenshot .NET deserialization code execution attempt

IPS-SWG

1 SID: 63135

Detects content exploiting CVE-2023-34634, a .NET deserialization flaw in the Greenshot screenshot tool that can allow code execution. The rule matches the serialized principal object payloads that public exploits use to reach unsafe deserialization.