CVE-2023-36266 describes a sensitive information disclosure vulnerability in Keeper Password Manager for Desktop (versions up to 16.10.2) and KeeperFill Browser Extensions (versions up to 16.5.4). The flaw allows local attackers to extract plaintext passwords from memory after a user is logged in, with some persistence even after logout. Rated Medium severity (CVSS 5.5), this local attack requires low privileges and complexity, potentially leading to high confidentiality impact. While the vendor disputes the nature of the vulnerability, exploit code (EDB-51623) is publicly available, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.10.2CPE matchmatch criteria | cpe:2.3:a:keepersecurity:keeper:16.10.2:*:*:*:*:*:*:* | ||
16.5.4CPE matchmatch criteria | cpe:2.3:a:keepersecurity:keeperfill:16.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.