Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-33901. PoCs published by gmikisilva.
AI-analyzed exploit summary This repository contains a functional Python script that demonstrates CVE-2024-33901, an information leak vulnerability in KeePassXC 2.7.7. The exploit creates a memory dump of the KeePassXC process and searches for password strings, confirming the vulnerability by extracting sensitive data from memory.
Description
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Exploits (1)
This repository contains a functional Python script that demonstrates CVE-2024-33901, an information leak vulnerability in KeePassXC 2.7.7. The exploit creates a memory dump of the KeePassXC process and searches for password strings, confirming the vulnerability by extracting sensitive data from memory.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N