logo

Critical Sandboxie Escape Flaws Grant Total SYSTEM Takeover

ID: 10b32941-f4f6-5499-8762-b2265449e9b9

STIX ID: report--10b32941-f4f6-5499-8762-b2265449e9b9

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

### Executive Summary: The report describes two critical Sandboxie vulnerabilities — a 32KB uninitialized stack memory leak combined with a stack buffer overflow (CVE-2026-34459) that exposes return addresses and stack cookies enabling ROP-based sandbox escapes and local SYSTEM escalation, and an INI CRLF injection (CVE-2026-34458) that lets standard users inject unrestricted configuration sections to achieve arbitrary file writes and privilege escalation; affected users should update from versions ≤1.17.2 to 1.17.3 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.