Executive brief
Sandboxie-Plus is a security tool used to run applications in isolated environments (sandboxes) to protect the rest of the computer from malicious software. A vulnerability in how the software handles configuration updates allows a standard user to bypass security restrictions and modify global settings. By exploiting this, an attacker can escape the sandbox and gain full control over the Windows operating system with SYSTEM-level privileges.
Technical details
An INI injection vulnerability exists in the background service of Sandboxie-Plus due to improper neutralization of CRLF sequences in IPC messages. The service intentionally skips authorization checks (bypassing EditAdminOnly and ConfigPassword) for settings starting with 'UserSettings_'. Attackers can use MSGID_SBIE_INI_ADD_SETTING or MSGID_SBIE_INI_SET_SETTING to inject CRLF characters into the 'value' or 'setting' parameters. When the service writes these unsanitized strings to the global Sandboxie.ini file, it allows the attacker to define new, unrestricted sandbox sections. This leads to sandbox escape and local privilege escalation to SYSTEM. The issue is fixed in version 1.17.3.
Affected products
- sandboxie-plus Sandboxie-Plus <= 1.17.2
Timeline
- 2026-03-29: patched: Version 1.17.3 released
- 2026-05-04: advisory: Vendor security advisory published via GitHub
- 2026-05-05: disclosed: CVE-2026-34458 published