PT-2026-37218 · Sandboxie · Sandboxie

Sammy12342

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-32603

CVSS v4.0

8.2

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Sandboxie versions prior to 1.17.3
Description A local denial of service exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL (Input/Output Control) to the 'DeviceSandboxieDriverApi' driver, triggering an immediate kernel crash resulting in a Blue Screen of Death (BSOD). This issue affects the Standard Sandbox configuration regardless of whether administrator privileges are dropped, but it does not affect the Security Hardened Sandbox configuration.
Recommendations Update to version 1.17.3. As a temporary workaround, use the Security Hardened Sandbox configuration.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-32603

Affected Products

Sandboxie