Critical Sandboxie Escape Flaws Grant Total SYSTEM Takeover
ID: 10b32941-f4f6-5499-8762-b2265449e9b9
STIX ID: report--10b32941-f4f6-5499-8762-b2265449e9b9
Feed Name: securityonline.info
### Executive Summary: The report describes two critical Sandboxie vulnerabilities — a 32KB uninitialized stack memory leak combined with a stack buffer overflow (CVE-2026-34459) that exposes return addresses and stack cookies enabling ROP-based sandbox escapes and local SYSTEM escalation, and an INI CRLF injection (CVE-2026-34458) that lets standard users inject unrestricted configuration sections to achieve arbitrary file writes and privilege escalation; affected users should update from versions ≤1.17.2 to 1.17.3 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
