
Cloud Vulnerability DB
A community-led vulnerabilities database
KeePassXC 2.7.7 contains a disputed vulnerability (CVE-2024-33900) that allows an attacker with victim's privileges to recover cleartext credentials via a memory dump. The vulnerability was discovered and reported in May 2024. The vendor disputes this issue, stating that memory-management constraints make this unavoidable in the current design and other realistic designs (NVD, CVE).
The vulnerability involves the ability to extract cleartext credentials from the process memory of KeePassXC when the database is open. According to the proof of concept, the credentials are stored as UTF-16 strings in the memory regions of the Qt framework. The attack has a reported success rate of 100% when the database is open, and lower probabilities (1 in 10) when the database is closed or locked (GitHub POC). The vulnerability has been classified under CWE-316 (Cleartext Storage of Sensitive Information in Memory) by CISA-ADP, with a CVSS v3.1 Base Score of 6.5 (MEDIUM) (NVD).
If exploited, the vulnerability allows attackers with local access to the victim's system to recover cleartext credentials from the KeePassXC process memory. This could lead to unauthorized access to all stored passwords and sensitive information in the KeePass database (NVD).
The vulnerability requires the attacker to have the same privileges as the victim and the ability to create a memory dump of the KeePassXC process. This can be achieved through various methods, such as using Windows Task Manager or VirtualBox debugvm. The exploit has been demonstrated to work consistently when the database is open, with reduced success rates when the database is closed or locked (GitHub POC).
The vendor has stated that this issue is not considered a vulnerability due to memory-management constraints in the current and other realistic designs. KeePassXC has previously documented their memory security approach, which includes various platform-specific protections such as disabling process memory reading and core dumps (KeePassXC Blog).
The issue has generated discussion within the security community, with some researchers suggesting that the ability to dump plaintext credentials from process memory when the database is unlocked is expected behavior rather than a security vulnerability. The focus has shifted to the possibility of non-zeroed freed memory being the potential cause of credential recovery when the database is locked (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."