PT-2026-37218 · Sandboxie · Sandboxie

Sammy12342

·

Published

2026-05-05

·

Updated

2026-05-06

·

CVE-2026-32603

CVSS v4.0

8.2

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Sandboxie versions prior to 1.17.3
Description A local denial of service exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL (Input/Output Control) to the 'DeviceSandboxieDriverApi' driver, triggering an immediate kernel crash resulting in a Blue Screen of Death (BSOD). This issue affects the Standard Sandbox configuration regardless of whether administrator privileges are dropped, but it does not affect the Security Hardened Sandbox configuration.
Recommendations Update to version 1.17.3. As a temporary workaround, use the Security Hardened Sandbox configuration.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32603

Affected Products

Sandboxie