PT-2025-50734 · Sophos · Sandboxie

Depthfirstdisclosures

·

Published

2025-12-11

·

Updated

2025-12-30

·

CVE-2025-64721

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sandboxie versions 1.16.6 and below
Description Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. The SYSTEM-level service SbieSvc.exe exposes the SbieIniServer::RC4Crypt function to sandboxed processes. This function adds a fixed header size to a caller-controlled value len without performing adequate overflow checks. Providing a large value len (for example, 0xFFFFFFF0) causes the allocation size to wrap around, resulting in a heap overflow when attacker-controlled data is copied into a buffer that is too small. Successful exploitation allows sandboxed processes to execute arbitrary code with SYSTEM privileges, leading to full host compromise.
Recommendations Update Sandboxie to version 1.16.7 or later.

Exploit

Fix

LPE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64721
GHSA-W476-J57G-96VP

Affected Products

Sandboxie