Password Manager: Controversial vulnerability in KeePass fixed

Share:

The developer has now closed a much-discussed security gap that made it easier for burglars to export passwords in the system with an update.

A vulnerability in the open source password manager KeePass caused discussions last week: burglars with user rights in the system were able to change the configuration of KeePass in such a way that a plain text export of the database was created without further feedback (CVE-2023-24055 ). With an updated version, the developer has now eliminated this behavior.

In version 2.53.1 he simply removed the “Export – No Key Repeat” guideline, which means that users are now always asked about a password database export. They now have to enter their master key, explains the KeePass changelog .

Originally, the developer took the view that “the password database does not need to be protected against an attacker who has such access to the local PC”. The explanation for this is fundamentally sound.

He explained that “it’s not really a security hole in KeePass”. Anyone who has access rights to the configuration file can usually access the entire user profile and thus carry out much more far-reaching attacks. Malicious actors could anchor malware in startup, change desktop shortcuts, modify registry values ​​or change configuration files of other software, such as causing a web browser to open a malicious website automatically. For users of the portable version, attackers with these rights could access the entire program directory and replace the KeePass file with malware.

Attackers with these rights can also attack KeePass itself, without access to the configuration file. For example, if a Trojan is active on the system, it can affect a password manager and other software such as web browsers in many ways. The passwords in the password manager must therefore always be considered compromised in the event of an infection. As KeePass put it, “KeePass cannot magically run securely in an insecure environment.”

With the option now chosen to remove the policy from the software, the developer has implemented the user’s request, for example in the Sourceforge discussion forum . The initial objection that an attacker with the appropriate rights in the system could re-enable the “Export – No Key Repeat” policy in the configuration file is superfluous as it has been completely removed.

However, the update does not change the fundamental problem that after a Trojan attack, the passwords of those affected must also be considered compromised despite the use of a password manager. These should still be changed immediately after a malware infection.

 

(c) heise

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:48 am, Jul 13, 2025
weather icon 17°C
L: 15° | H: 18°
scattered clouds
Humidity: 84 %
Pressure: 1015 mb
Wind: 3 mph NE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 29%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:58 am
Sunset: 9:13 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 7 mph 79 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 27°°C 0 mm 0% 15 mph 72 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 21°°C 1 mm 100% 15 mph 70 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
16° | 27°°C 0.48 mm 48% 13 mph 79 % 1015 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
17° | 21°°C 1 mm 100% 5 mph 89 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
15° | 16°°C 0 mm 0% 4 mph 79 % 1015 mb 0 mm/h
Today 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 73 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
24° | 24°°C 0 mm 0% 4 mph 49 % 1013 mb 0 mm/h
Today 1:00 pm
weather icon
28° | 28°°C 0 mm 0% 3 mph 37 % 1011 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 2 mph 30 % 1010 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 28°°C 0 mm 0% 4 mph 31 % 1009 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 7 mph 52 % 1011 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 56 % 1011 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,410.89
0.04%
Ethereum(ETH)
€2,519.78
0.10%
XRP(XRP)
€2.34
1.01%
Tether(USDT)
€0.86
0.00%
Solana(SOL)
€137.86
-0.87%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.169112
-0.27%
Shiba Inu(SHIB)
€0.000011
0.42%
Pepe(PEPE)
€0.000010
0.06%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top