PT-2025-50734 · Sophos · Sandboxie
Depthfirstdisclosures
·
Published
2025-12-11
·
Updated
2025-12-30
·
CVE-2025-64721
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sandboxie versions 1.16.6 and below
Description
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. The SYSTEM-level service
SbieSvc.exe exposes the SbieIniServer::RC4Crypt function to sandboxed processes. This function adds a fixed header size to a caller-controlled value len without performing adequate overflow checks. Providing a large value len (for example, 0xFFFFFFF0) causes the allocation size to wrap around, resulting in a heap overflow when attacker-controlled data is copied into a buffer that is too small. Successful exploitation allows sandboxed processes to execute arbitrary code with SYSTEM privileges, leading to full host compromise.Recommendations
Update Sandboxie to version 1.16.7 or later.
Exploit
Fix
LPE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sandboxie