Executive brief
Sandboxie-Plus is a security tool used to run applications in an isolated environment to prevent them from making permanent changes to the system. A flaw in how the software handles internal messages allows a malicious program already on the computer to crash the security service or potentially take full control of the Windows operating system. This could allow a standard user to gain administrative (SYSTEM) privileges, bypassing security boundaries.
Technical details
A stack-based buffer overflow exists in the SbieIniServer::RunSbieCtrl handler within Sandboxie-Plus versions 1.17.2 and earlier. The vulnerability is triggered when the MSGID_SBIE_INI_RUN_SBIE_CTRL message is processed; for non-sandboxed callers, the handler uses memcpy to copy the message payload into a fixed-size 128-character WCHAR buffer (ctrlCmd) without length validation. Because the service pipe is created with a NULL DACL, any local interactive process can connect to the pipe and send an oversized payload. Successful exploitation can lead to local privilege escalation (LPE) to SYSTEM or a crash of the SbieSvc service. The issue is resolved in version 1.17.3.
Affected products
- sandboxie-plus Sandboxie-Plus <= 1.17.2
Timeline
- 2026-05-04: advisory: Vendor advisory published on GitHub
- 2026-05-05: disclosed: CVE-2026-34461 published
- 2026-05-05: patched: Fixed in version 1.17.3