NA

CVE-2023-38840

Published: 15/08/2023 Updated: 22/08/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

Vulnerable Product Search on Vulmon Subscribe to Product

bitwarden bitwarden

Github Repositories

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

BW-Dump Updated 2: This vulnerability was assigned CVE-2023-38840 Updated: A patch was released on GitHub pull request (5813) which fixes the vulnerability The affected versions are Bitwarden Desktop 202370 and below Description A proof-of-concept tool that extracts the master password from a locked Bitwarden vault (must be unlocked at least once) from Windows systems It