Denis Andzakovic, a security researcher at Security Assessment, has created a tool that can trick the KeePass password manager into exporting an internal database of its passwords as a CSV file, showing the user's account credentials in plain text.
The tool, ironically named KeeFarce, is available on GitHub and despite its powerful features, it only works if the user has KeePass 2.x open on their computer when KeeFarce is run.
KeePass manager that allows users to record account details for various websites and applications and then automatically fills in those details when users open or access those applications/websites at some other time in the future.
KeePass and other similar applications allow users to improve their online password policy by setting complex passphrases for their accounts.
Tools like KeePasshave become essential for many users, who use them on a daily basis, so that they are not forced to write their passwords on paper, keep them in text files in Dropbox, or memorize complex and random character sequences.
To look deeper, KeeFarce uses a technique called DLL injection, which allows third-party applications to intervene in the processes of another application, forcing it to load an external DLL file.
The technique is quite old, but it also requires administrator rights on the computer where it is applied.
Therefore, KeeFarce, despite its powerful capabilities, is pretty much useless unless the computer has already been compromised and the attackers have gained administrator privileges. In that case, users will have bigger things to worry about, since in most programs they will probably already be logged in and KeeFarce becomes just a small cog in a larger machine.
As Andzakovic said in an interview with ArsTechnica, his tool is compatible with a Metasploit hacking framework.
In KeePass's defense, its authors have never said their application was 100% secure. The company has stated multiple times in the past that its tool can be compromised in large-scale attacks running on the system and can only protect users from basic tools like keyloggers, not full-fledged hacking frameworks like Metasploit.

