CVE-2023-32784 is a local memory-disclosure vulnerability in KeePass 2.x versions later than 2.0 and before 2.54. The custom SecureTextBoxEx control used for masked password entry creates residual managed-string artifacts for characters typed into the field. These artifacts can remain recoverable in process memory and in memory-backed persistence artifacts after the database is locked or the KeePass process has exited. An attacker can recover the master password in cleartext except for its first character; enumeration of that remaining character makes this effectively a full master-password disclosure. KeePass 1.x, KeePassXC, and Strongbox are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a two-file standalone Python proof/exploitation utility for CVE-2023-32784, a KeePass 2.x memory-disclosure flaw. README.md documents affected versions, prerequisites, mitigation, and command-line usage. keepass_dumper.py is the executable entry point and uses only Python standard-library modules, notably mmap for efficient read-only scanning of large memory artifacts and subprocess for optional KeePassXC CLI validation. The scanner searches byte-by-byte for UTF-16 little-endian bullet characters (`●`, bytes CF 25) followed by a candidate character, matching residual SecureTextBoxEx render strings whose bullet-run length identifies the password position. It accepts printable ASCII by default, optionally supports extended characters, limits bullet runs to reduce false positives, and collects/sorts candidates according to a frequency-prioritized charset. Position one remains represented by `●` because the vulnerability does not expose it. The tool can print or save templates and, with a local KDBX file, brute-force placeholder positions through `keepassxc-cli db-info` until a password is accepted. It is an offline forensic credential-recovery exploit rather than a network-facing exploit; it contains no hard-coded remote URLs, IP addresses, domains, persistence behavior, or shell payload.
This repository is a small DFIR/exploit-analysis lab centered on a malicious PowerShell infostealer and a helper decoder. It contains 5 files: a README overview, a detailed markdown writeup, a Python decoder, and the recovered PowerShell payload under evidence/. The main offensive artifact is evidence/xxxmmdcclxxxiv.ps1, an obfuscated PowerShell script targeting KeePass on Windows. Its logic is clear despite variable-name obfuscation: it checks for ProcDump at C:\Tools\procdump.exe, downloads Procdump.zip from Sysinternals if missing, locates a running KeePass process, launches ProcDump with -accepteula -ma to create a full memory dump, XORs the dump with key 0x41, Base64-encodes it, writes an intermediate file, and exfiltrates the result over a raw TCP socket to an attacker IP encoded as 0xa0a5e6a on port 1337. The accompanying writeup states the same script also steals Database1337.kdbx, obfuscates it with XOR key 0x42, and exfiltrates it on port 1338. The decoded C2 IP documented in the writeup is 10.10.94.106, and the initial malicious script was served over HTTP from 10.10.94.106:1339. The Python file decoder.py is not an exploit itself; it is a forensic utility that reverses the exfiltration chain from tshark output by converting hex packet payloads to bytes, Base64-decoding them, and XOR-decoding with a supplied key. Overall, this is a valid operational proof-of-concept repository documenting credential theft via KeePass memory dumping and subsequent abuse of CVE-2023-32784 to recover the master password from the stolen dump.
This repository is a small standalone Python proof-of-concept for CVE-2023-32784 affecting KeePass 2.x. It contains only two files: a short README and a single executable script, cracker.py. The script is not a remote exploit and does not perform network activity despite importing the requests module, which is unused. Its attack vector is local: it requires a previously obtained KeePass memory dump file as input. The main logic in cracker.py uses argparse to accept one positional argument, the dump filename. It opens the file in binary mode and processes it in 512 KB chunks. The code searches for the UTF-16LE byte pattern corresponding to the masked password bullet character U+25CF (0xCF 0x25 in little-endian form). After detecting one or more consecutive bullet characters, it attempts to decode the following two-byte sequence as UTF-16LE and checks whether the resulting character falls within a broad printable range (0x20-0xFF). Matching characters are stored in a candidates structure keyed by string position and are also printed as progressively reconstructed strings via messages like 'Found: ...'. Operationally, the script is intended to recover candidate password characters or partial password strings from memory artifacts left behind by KeePass 2.x password entry handling. It does not include a weaponized payload, shell, persistence, or post-exploitation capability. It is best classified as a local post-compromise/offline analysis POC that helps reconstruct a KeePass master password from a dump rather than directly compromising a target system. No fingerprintable network endpoints, IPs, domains, registry keys, or hardcoded remote targets are present in the code. The only meaningful endpoint-like artifact is the user-provided local file path to the dump being analyzed.
This repository contains a PowerShell script ('BruteForce-to-KeePass.ps1') and a README. The script is designed to assist in brute-forcing the master password of a KeePass database (kdbx file), particularly in scenarios where part of the password is known (e.g., after exploiting CVE-2023-32784 with another tool). The user provides a set of possible characters and a known suffix; the script generates all possible combinations, writes them to 'Dictionary.txt', and attempts to open the KeePass database with each candidate using the KeePass .NET assemblies. If the correct password is found, it is displayed to the user. The script requires local access to the KeePass database file and the KeePass binaries installed on the system. The README provides context, usage instructions, and credits to related tools. The attack vector is local, targeting files on disk, and the main endpoints are file paths for KeePass binaries and the database file.
This repository contains a Python proof-of-concept exploit for CVE-2023-32784, targeting KeePass 2.X password manager. The exploit leverages a vulnerability where the KeePass master password may be left in process memory, allowing an attacker with access to a memory dump to extract the master password or significant portions of it. The main script, 'keepass_dump.py', provides several features: it can scan the dump file for master password characters using known string jump points for efficiency, perform a full scan if needed, skip repeated bytes to speed up scanning, attempt to recover unknown characters by reconstructing possible combinations, and search for passwords using a supplied wordlist. The script is run from the command line and requires the user to supply a memory dump file. Optional arguments allow for outputting results to a file and customizing the search process. The exploit is a standalone PoC and does not require or use any exploit framework. The README provides detailed usage instructions, feature descriptions, and references to the original vulnerability and related research.
This repository contains a proof-of-concept exploit for CVE-2023-32784, targeting KeePass 2.x (prior to version 2.54) on Windows, Linux, and macOS. The exploit is implemented in C# (.NET) and consists of a single main code file (Program.cs) and a project file. The tool scans a provided memory dump (such as a process dump, swap file, hibernation file, or crash dump) for patterns left by KeePass's SecureTextBoxEx password entry control. By analyzing these patterns, it reconstructs the KeePass master password, typically recovering all but the first character. The tool can also generate a list of all possible passwords starting from the second character. No code execution on the target system is required; only access to a memory dump is needed. The repository includes a README with detailed usage instructions, affected and unaffected products, and mitigation advice. The exploit is a local attack vector, requiring physical or logical access to the target's memory files.
This repository contains a Go-based proof-of-concept exploit for CVE-2023-32784, a vulnerability in KeePass 2.X (prior to version 2.54) that allows partial recovery of the master password from a memory dump of an unlocked KeePass process. The main file, 'main.go', implements the logic to parse a memory dump file, searching for a specific byte pattern (0xCF 0x25) that precedes password characters in memory. The tool reconstructs possible characters for each password position, outputs a possible passphrase, and generates a JohnTheRipper mask to facilitate further password cracking. The repository is structured with standard Go project files and build configurations, and the exploit is run locally by providing a memory dump file as input. No network or remote attack vectors are present; the exploit is strictly local and requires access to a memory dump file.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-32784, targeting KeePass 2.53 on Linux. The exploit is implemented in a single C file (dump_pwd.c) and is accompanied by a README.md that explains the vulnerability and usage. The exploit works by scanning the /proc filesystem for KeePass processes, dumping their memory via /proc/<pid>/mem, and parsing the dump to extract the master password (with the first character missing due to the way KeePass handles input). The exploit requires high privileges (typically root) to access the necessary /proc files, making it a local attack vector. The code is a PoC and does not provide a weaponized or automated attack, but demonstrates the vulnerability and extraction technique. No network endpoints are involved; all actions are performed locally on the target system.
This repository provides a proof-of-concept exploit for CVE-2023-32784, a vulnerability in KeePass Password Manager that allows extraction of the master password from a memory dump. The main file, 'poc.py', is a Python script that takes a memory dump file as input, scans for specific byte patterns associated with KeePass master key fragments, and reconstructs possible master passwords. The script outputs these candidate passwords, which can then be further brute-forced using an external shell script (as suggested in the README) or tested manually. The exploit is local in nature, requiring access to a memory dump from a target machine. The README provides usage instructions and context, noting that the exploit is more reliable on physical machines than virtual ones. No network endpoints or remote attack vectors are present; the only fingerprintable endpoint is the file path to the memory dump provided by the user.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Уязвимость в KeePass 2.x, позволяющая восстановить мастер-пароль из дампа памяти из-за того, что masked input в SecureTextBoxEx оставляет строковые артефакты в managed heap .NET.
A memory disclosure vulnerability affecting KeePass 2.x installations prior to version 2.54.
A high-severity local information disclosure vulnerability in KeePass 2.x prior to 2.54, caused by SecureTextBoxEx handling that can leave password characters in memory, allowing extraction of sensitive data including the master password from memory dumps.
A KeePass memory-disclosure vulnerability caused by its SecureTextBoxEx password-entry control retaining traces of entered master-password characters in memory. An attacker with existing access to a vulnerable machine can recover all but the first master-password character, making compromise of the complete password trivial by enumeration.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.