CVE-2024-33900
NixOS vulnerability analysis and mitigation

Overview

KeePassXC 2.7.7 contains a disputed vulnerability (CVE-2024-33900) that allows an attacker with victim's privileges to recover cleartext credentials via a memory dump. The vulnerability was discovered and reported in May 2024. The vendor disputes this issue, stating that memory-management constraints make this unavoidable in the current design and other realistic designs (NVD, CVE).

Technical details

The vulnerability involves the ability to extract cleartext credentials from the process memory of KeePassXC when the database is open. According to the proof of concept, the credentials are stored as UTF-16 strings in the memory regions of the Qt framework. The attack has a reported success rate of 100% when the database is open, and lower probabilities (1 in 10) when the database is closed or locked (GitHub POC). The vulnerability has been classified under CWE-316 (Cleartext Storage of Sensitive Information in Memory) by CISA-ADP, with a CVSS v3.1 Base Score of 6.5 (MEDIUM) (NVD).

Impact

If exploited, the vulnerability allows attackers with local access to the victim's system to recover cleartext credentials from the KeePassXC process memory. This could lead to unauthorized access to all stored passwords and sensitive information in the KeePass database (NVD).

Exploitability

The vulnerability requires the attacker to have the same privileges as the victim and the ability to create a memory dump of the KeePassXC process. This can be achieved through various methods, such as using Windows Task Manager or VirtualBox debugvm. The exploit has been demonstrated to work consistently when the database is open, with reduced success rates when the database is closed or locked (GitHub POC).

Mitigation and workarounds

The vendor has stated that this issue is not considered a vulnerability due to memory-management constraints in the current and other realistic designs. KeePassXC has previously documented their memory security approach, which includes various platform-specific protections such as disabling process memory reading and core dumps (KeePassXC Blog).

Community reactions

The issue has generated discussion within the security community, with some researchers suggesting that the ability to dump plaintext credentials from process memory when the database is unlocked is expected behavior rather than a security vulnerability. The focus has shifted to the possibility of non-zeroed freed memory being the potential cause of credential recovery when the database is locked (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097CRITICAL9.1
  • NixOS logoNixOS
  • python3-samba-test
NoYesAug 20, 2026
CVE-2026-11861HIGH8.1
  • NixOS logoNixOS
  • samba-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • samba-test-libs-debuginfo
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • samba-ldb-ldap-modules-debuginfo
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management