There exists a .NET deserialization vulnerability in Greenshot versions 1.3.274 and below. The deserialization allows the execution of commands when a user opens a Greenshot file. The commands execute under the same permissions as the Greenshot service. Typically, it is the logged in user.
417583375a798246fd4576d2e33b79c589cc0fa3d06430926abf50d5142f368a
GreenShot version 1.2.10 suffers from an insecure deserialization arbitrary code execution vulnerability.
b26edbfe421934dee223c0345040828fff445263bcf0bca848f9ee4110b474ef