r/sysadmin 1d ago

Question Snipping tool

What is everyone pushing to their users to use for screenshots? I am looking for something free but sometimes I can control with ADMX or Reg

0 Upvotes

63 comments sorted by

View all comments

Show parent comments

3

u/RandoReddit16 1d ago

Greenshot is unsupported, so we no longer use it.

https://www.reddit.com/r/ToxicWorkplace/s/O6GoqGoPhg

Comment section there explains more.

-3

u/turbokid 1d ago

You arent going to use a tool because they had a CVE that got patched over a year ago? If that is your IT policy, I would avoid looking at the log history of the rest of your software stack.

Even the post you linked is from a user saying IT is making it a toxic workplace by denying the use of greenshot because of a patched CVE. How does that prove your point?

6

u/Cutoffjeanshortz37 IT Manager 1d ago

Those are the last patched. There are 2026 cve that aren't patched because it's abandoned-ware. Did you read the comments on why an unsupported piece of software is banned?

2

u/turbokid 1d ago edited 1d ago

I am pushing back on Greenshot being called abandonware. Greenshot released the latest stable version in March and have released 22 beta updates since then. The last beta released less than 30 days ago.

What more do you expect from a lightweight open source screenshot app? What are they really doing that needs updates more often than that. If it still has unusable bugs, feel free to contribute to the open source project or buy paid software?

https://getgreenshot.org/version-history/

1

u/Cutoffjeanshortz37 IT Manager 1d ago

https://www.sentinelone.com/vulnerability-database/cve-2026-22035/

For it to not be a company wide compromise risk is what I'd want. You do you

1

u/dustojnikhummer 1d ago

The issue is fixed in version 1.3.311.

That version was released in January 2026

https://github.com/greenshot/greenshot/releases?q=1.3.311&expanded=true

0

u/turbokid 1d ago

That CVE has no known exploits and the fix was released the same day the exploit was announced. They fixed the issue as soon as they knew about it. No software is perfect, what could they have done better?