PT-2025-31199 · Sandboxie · Sandboxie
Love-Code-Yeyixiao
·
Published
2025-07-29
·
Updated
2025-07-29
·
CVE-2025-54422
Love-Code-Yeyixiao
·
Published
2025-07-29
·
Updated
2025-07-29
·
CVE-2025-54422
6.9
Medium
Base vector | Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Sandboxie versions 1.16.1 and earlier
Description:
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. A critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, potentially exposing them to interception. The vulnerability is particularly severe during password modification operations, where both old and new passwords are passed as plaintext command-line arguments to the `Imbox` process without encryption or obfuscation. This allows any process within the user session, including unprivileged processes, to retrieve these sensitive credentials by reading the command-line arguments, bypassing standard privilege requirements.
Recommendations:
Update to Sandboxie version 1.16.2 or later.
Exploit
Fix
Cleartext Storage of Sensitive Information
Insufficiently Protected Credentials