PT-2025-31199 · Sandboxie · Sandboxie

Love-Code-Yeyixiao

·

Published

2025-07-29

·

Updated

2025-07-29

·

CVE-2025-54422

CVSS v4.0
6.9
VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Name of the Vulnerable Software and Affected Versions:

Sandboxie versions 1.16.1 and earlier

Description:

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. A critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, potentially exposing them to interception. The vulnerability is particularly severe during password modification operations, where both old and new passwords are passed as plaintext command-line arguments to the `Imbox` process without encryption or obfuscation. This allows any process within the user session, including unprivileged processes, to retrieve these sensitive credentials by reading the command-line arguments, bypassing standard privilege requirements.

Recommendations:

Update to Sandboxie version 1.16.2 or later.

Exploit

Fix

Cleartext Storage of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-54422
GHSA-JP7R-VGV9-43P7

Affected Products

Sandboxie