logo

Exploitable and unpatched KeePass vulnerability: everything you need to know

ID: bfe0bac6-4ce9-5672-b3ab-ae3206ad25c0

STIX ID: report--bfe0bac6-4ce9-5672-b3ab-ae3206ad25c0

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2023-05-23

Date Updated: 2026-05-01

...
...

CVE-2023-32784 is a KeePass vulnerability that leaves characters of the master password in memory via the SecureTextBoxEx control, enabling recovery of the password (public PoC published). The report notes affected versions, Wiz telemetry showing nontrivial exposure (15% of environments have KeePass; 10% run vulnerable versions), recommends upgrading to KeePass 2.54.0 and system-level mitigations, and warns exploitation is likely while unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.