Sandboxie Escape Flaw Could Let Attackers Gain SYSTEM-Level Privileges
ID: ee99a730-816a-5e76-80bd-791a9ae0589e
STIX ID: report--ee99a730-816a-5e76-80bd-791a9ae0589e
Feed Name: GBHackers
Threat Score
Security researchers disclosed multiple critical vulnerabilities in Sandboxie and Sandboxie-Plus that allow sandbox escapes and SYSTEM-level privilege escalation (notably a stack-based buffer overflow in SbieSvc), configuration-file injection permitting elevation, a driver-triggered kernel crash (BSOD), and a weakened password hashing implementation; maintainers released patches in versions 1.17.3 through 1.17.5 and users are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
