PT-2025-31199 · Sandboxie · Sandboxie
Love-Code-Yeyixiao
·
Published
2025-07-29
·
Updated
2025-08-04
·
CVE-2025-54422
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sandboxie versions 1.16.1 and earlier
Description
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. A critical security issue exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, potentially exposing them to interception. The issue is particularly severe during password modification operations, where both old and new passwords are passed as plaintext command-line arguments to the
Imbox process without encryption or obfuscation. This allows any process within the user session, including unprivileged processes, to retrieve these sensitive credentials by reading the command-line arguments, bypassing standard privilege requirements.Recommendations
Update Sandboxie to version 1.16.2 or later.
Exploit
Fix
Cleartext Storage of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sandboxie