CVE-2023-23349: Kaspersky Password Manager For Windows
Low severity, CVSS 2.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the saved credentials, and the KPM extension must autofill these credentials. The attacker must then launch a malware module to steal those specific credentials.
Affected products
- Kaspersky Kaspersky Password Manager For Windows: before 24.0.0.427 (fixed in 24.0.0.427)
Published 2024-03-22. Last modified 2026-06-17.