Password Manager: Controversial vulnerability in KeePass fixed

Teilen:

The developer has now closed a much-discussed security gap that made it easier for burglars to export passwords in the system with an update.

A vulnerability in the open source password manager KeePass caused discussions last week: burglars with user rights in the system were able to change the configuration of KeePass in such a way that a plain text export of the database was created without further feedback (CVE-2023-24055 ). With an updated version, the developer has now eliminated this behavior.

In version 2.53.1 he simply removed the “Export – No Key Repeat” guideline, which means that users are now always asked about a password database export. They now have to enter their master key, explains the KeePass changelog .

Originally, the developer took the view that “the password database does not need to be protected against an attacker who has such access to the local PC”. The explanation for this is fundamentally sound.

He explained that “it’s not really a security hole in KeePass”. Anyone who has access rights to the configuration file can usually access the entire user profile and thus carry out much more far-reaching attacks. Malicious actors could anchor malware in startup, change desktop shortcuts, modify registry values ​​or change configuration files of other software, such as causing a web browser to open a malicious website automatically. For users of the portable version, attackers with these rights could access the entire program directory and replace the KeePass file with malware.

Attackers with these rights can also attack KeePass itself, without access to the configuration file. For example, if a Trojan is active on the system, it can affect a password manager and other software such as web browsers in many ways. The passwords in the password manager must therefore always be considered compromised in the event of an infection. As KeePass put it, “KeePass cannot magically run securely in an insecure environment.”

With the option now chosen to remove the policy from the software, the developer has implemented the user’s request, for example in the Sourceforge discussion forum . The initial objection that an attacker with the appropriate rights in the system could re-enable the “Export – No Key Repeat” policy in the configuration file is superfluous as it has been completely removed.

However, the update does not change the fundamental problem that after a Trojan attack, the passwords of those affected must also be considered compromised despite the use of a password manager. These should still be changed immediately after a malware infection.

 

(c) heise

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:48 am, Juli 13, 2025
Wetter-Symbol 18°C
L: 16° | H: 19°
overcast clouds
Luftfeuchtigkeit: 78 %
Druck: 1013 mb
Wind: 7 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 6 mph 78 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 71 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 1 mm 100% 17 mph 85 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
14° | 27°°C 0.11 mm 11% 11 mph 85 % 1017 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
18° | 27°°C 1 mm 100% 13 mph 95 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 23°°C 0 mm 0% 4 mph 78 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
21° | 27°°C 0 mm 0% 3 mph 66 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
26° | 30°°C 0 mm 0% 0 mph 44 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 52 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 71 % 1011 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,960.98
0.11%
Ethereum(ETH)
€2,535.20
-0.14%
XRP(XRP)
€2.40
0.85%
Fesseln(USDT)
€0.86
-0.01%
Solana(SOL)
€138.81
-0.73%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.170584
-0.97%
Shiba Inu(SHIB)
€0.000011
-0.55%
Pepe(PEPE)
€0.000010
-1.13%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen