HIGH🇵🇱 Wersja polska

CVE-2026-32603

CVSS 8.2v4.0pub. 2026-05-05upd. 2026-07-25

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDriverApi driver, triggering an immediate kernel crash (BSOD). The vulnerability affects the Standard Sandbox configuration both with and without dropped administrator privileges, but does not affect the Security Hardened Sandbox configuration. This issue has been fixed in version 1.17.3. Users who cannot update can use the Security Hardened Sandbox configuration as a workaround.

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sandboxie Plus Sandboxie

    APP
    Sandboxie-Plus
    < 1.17.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-34458CRITICAL9.3PL ✓same product

INI injection w Sandboxie-Plus umożliwia eskalację uprawnień do SYSTEM

CVE-2025-64721CRITICAL9.9PL ✓same product

Sandboxie-Plus: heap overflow w SbieSvc.exe umożliwia RCE jako SYSTEM

CVE-2024-49360CRITICAL9.2PL ✓same product

Sandboxie: nieautoryzowany odczyt plików między użytkownikami (path traversal)

CVE-2018-18748CRITICAL10.0PL ✓same product

Sandboxie 5.26 — potencjalny Sandbox Escape przez skrypt Python

CVE-2026-34459HIGH8.8same product

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier,...