CVE-2023-23349: Low severity Kaspersky Kaspersky Password Manager vulnerability
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23349?
CVE-2023-23349 has been rated as a high severity vulnerability due to its potential to expose sensitive user credentials.
How do I fix CVE-2023-23349?
To fix CVE-2023-23349, users should update to the latest version of Kaspersky Password Manager provided by Kaspersky.
What impact does CVE-2023-23349 have on users?
CVE-2023-23349 allows a local user to recover auto-filled credentials from memory, potentially leading to unauthorized access to user accounts.
Are all versions of Kaspersky Password Manager affected by CVE-2023-23349?
Yes, CVE-2023-23349 affects Kaspersky Password Manager for Windows when used with the Google Chrome extension.
Can CVE-2023-23349 be exploited remotely?
No, exploitation of CVE-2023-23349 requires local access to the user's machine.