CVE-2023-32784
HIGH 7.5EPSS 4.4%
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 4.40% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2023-05-15
- Updated
- 2025-01-23
Proof-of-concept exploits (12)
- vdohney/keepass-password-dumper653★ · 2023-08-17
- 4m4Sec/CVE-2023-327840★ · 2023-08-30
- CTM1/CVE-2023-32784-keepass-linux3★ · 2024-01-27
- Cmadhushanka/CVE-2023-32784-Exploitation0★ · 2024-07-10
- G4sp4rCS/CVE-2023-32784-password-combinator-fixer0★ · 2025-03-31
- Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-327840★ · 2024-06-25
- dawnl3ss/CVE-2023-327840★ · 2023-08-30
- dev0558/CVE-2023-32784-EXPLOIT-REPORT0★ · 2024-12-04
- hau-zy/KeePass-dump-py0★ · 2023-06-04
- mister-turtle/cve-2023-327844★ · 2024-02-01
- ynuwenhof/keedump10★ · 2023-05-21
- z-jxy/keepass_dump29★ · 2023-11-04