Junglewise Threat Intelligence

CVE-2026-34461: Sandboxie-Plus stack buffer overflow in SbieIniServer RunSbieCtrl

CVE-2026-34461 · Severity: high · CVSS 7.8 · Published 2026-05-05

Technologies: Sandboxie-Plus, Sandboxie-Plus Sandboxie. Vendors: Sandboxie-Plus.

Executive brief

Sandboxie-Plus is a security tool used to run applications in an isolated environment to prevent them from making permanent changes to the system. A flaw in how the software handles internal messages allows a malicious program already on the computer to crash the security service or potentially take full control of the Windows operating system. This could allow a standard user to gain administrative (SYSTEM) privileges, bypassing security boundaries.

Technical details

A stack-based buffer overflow exists in the SbieIniServer::RunSbieCtrl handler within Sandboxie-Plus versions 1.17.2 and earlier. The vulnerability is triggered when the MSGID_SBIE_INI_RUN_SBIE_CTRL message is processed; for non-sandboxed callers, the handler uses memcpy to copy the message payload into a fixed-size 128-character WCHAR buffer (ctrlCmd) without length validation. Because the service pipe is created with a NULL DACL, any local interactive process can connect to the pipe and send an oversized payload. Successful exploitation can lead to local privilege escalation (LPE) to SYSTEM or a crash of the SbieSvc service. The issue is resolved in version 1.17.3.

Affected products

  • sandboxie-plus Sandboxie-Plus <= 1.17.2

Timeline

  • 2026-05-04: advisory: Vendor advisory published on GitHub
  • 2026-05-05: disclosed: CVE-2026-34461 published
  • 2026-05-05: patched: Fixed in version 1.17.3

References

Related threats