CVE-2023-32784General(keepass / keepass)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for keepass keepass systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keepass

Threat summary

  • Public PoC and exploit tooling are both present
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 7 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-04); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
keepass

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-03-04: 2Mentions · 2026-04-24: 1Mentions · 2026-05-07: 1Mentions · 2026-06-28: 1Mentions · 2026-07-03: 1Mentions · 2026-08-02: 1Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-08-02: 1Exploit Tool / Code · 2026-03-04: 1Technical Details · 2026-03-04: 1Technical Details · 2026-09-09: 103-0404-2405-0706-2807-0308-0209-09
Signal classification2 categories
General
787.5%
PoC
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-042
General1PoC1
2026-04-241
General1
2026-05-071
General1
2026-06-281
General1
2026-07-031
General1
2026-08-021
General1
2026-09-091
General1
Full discourse8 posts
  • xrunner55@TheXrunner55
    General

    @TJMartinell1 @Rianstone Keep it up to date though. I popped a few keepass vaults before. https://www.cyberis.com/article/exploiting-keepass-cve-2023-32784

    Post summary

    The tweet references an article about exploiting Keepass CVE‑2023‑32784 and hints at prior exploitation, but it lacks direct PoC code, exploit details, or patch information.

    1003055
    514 followersView on X
  • PT Cyber Analytics@ptca_team
    General

    🔜Coming soon: a deep dive into password manager security. Exploring how password managers are designed to protect your credentials, where their security can break down, with real-world examples including the KeePass vulnerability (CVE-2023-32784), and practical ways to minimize the risks. Don't miss it🙌

    Post summary

    The tweet merely announces an upcoming discussion about password manager security that will reference CVE‑2023‑32784, but it provides no technical details, exploit code, or mitigation information.

    0002079
    11 followersView on X
  • r3m8@_r3m8
    General

    @JohnGrf3891 @gchampeau Pour prendre un exemple de Keepass (CVE-2023-32784), un compte administrateur pouvait obtenir le mot de passe maître en dumpant la mémoire ; mais on s'en fiche complètement, parce qu'il pourrait tout autant mettre un keylogger et arriver au même résultat, plus rapidement.

    Post summary

    The post notes a memory‑dump exploitation path for CVE‑2023‑32784 but does not provide a PoC, exploit code, or indicate active use, rendering it a general mention.

    1000033
    74 followersView on X
  • positive status@relax3fcy
    General

    CVE-2023-32784 https://t.co/O26QhTU72E

    Post summary

    The tweet merely lists CVE-2023-32784 with a URL, without any further details on the vulnerability or related exploits.

    0001031
    56 followersView on X
  • Ez@CristianPes
    General

    @thefuzzstone Really? Google about that CVE-2023-32784

    Post summary

    The tweet merely prompts users to search online for CVE-2023-32784, offering no substantive information.

    10000169
    166 followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    General

    9/10 Key takeaways: → Default creds are still the #1 low-hanging fruit → Sensitive data in ticketing system comments is more common than you think → CVE-2023-32784 is a reminder: secrets in memory are secrets exposed → Know your key format conversions

    Post summary

    The post references the known CVE‑2023‑32784 as a reminder about memory‑exposed secrets but provides no further technical, exploit, or patch details.

    1000059
    3 followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    PoC

    5/10 Home dir has http://RT30000.zip. Unzip reveals a .dmp and .kdbx file a KeePass memory dump + database. CVE-2023-32784 lets you extract the master password from process memory. git clone https://github.com/z-jxy/keepass_dump

    Post summary

    The snippet provides a GitHub repository and ZIP containing a KeePass memory dump, linking to CVE‑2023‑32784 and indicating a proof‑of‑concept for extracting the master password from process memory.

    1000073
    3 followersView on X
  • Yoyi@juany_yoyi
    General

    @UK_Daniel_Card But, its for CVE-2023-32784 rigth?

    Post summary

    The tweet merely questions whether CVE-2023-32784 is the correct CVE, without providing any additional information.

    0000053
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkeepasskeepass---

Explore more