PT-2018-14624 · Sandboxie · Sandboxie
Published
2018-10-28
·
Updated
2025-08-04
·
CVE-2018-18748
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sandboxie version 5.26
Description
The issue allows a sandbox escape via an
import os statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. The vendor disputes this issue, stating that the observed behavior is consistent with the product's intended functionality.Recommendations
For Sandboxie version 5.26, as a temporary workaround, consider restricting the use of the
os.system() function within sandboxed environments to minimize the risk of exploitation. Additionally, avoid using the os module in sandboxed Python scripts until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sandboxie