CVE-2026-34459Disclosure(sandboxie-plus / sandboxie)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sandboxie-plus sandboxie systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that can be chained for sandbox escape. First, when a sandboxed process sends an IPC request with cbSize set to 0, up to 32KB of uninitialized stack memory from the service process is returned, leaking return addresses and stack cookies which bypass ASLR and /GS protections. Second, the handler performs a memcpy with an attacker-controlled length without verifying it fits within the 32KB stack buffer, enabling a stack buffer overflow. By chaining the information leak with the overflow, a sandboxed process can execute a ROP chain to achieve SYSTEM privilege escalation, even from a Security Hardened Sandbox. Hardware-enforced shadow stacks (Intel CET) prevent the ROP chain execution but do not mitigate the information leak. This issue has been fixed in version 1.17.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxie

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-05); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
sandboxie

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-08: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-08: 105-0505-08
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure2General1
2026-05-081
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Security researchers expose catastrophic flaws in Sandboxie. CVE-2026-34459 enables a direct sandbox escape to SYSTEM privileges. Update to v1.17.3 today. #Sandboxie #CyberSecurity #InfoSec #CVE #SandboxEscape #ZeroDay #ExploitAlert #WindowsSecurity https://securityonline.info/sandboxie-critical-escape-vulnerabilities-cve-2026-34459-system-privilege/ https://t.co/DEtVgOUUlX

    Post summary

    Researchers disclosed CVE‑2026‑34459 allows a sandbox escape to SYSTEM privileges, and the vendor has released update v1.17.3 to mitigate the flaw.

    05010504
    11.8K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34459 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave … https://www.cve.org/CVERecord?id=CVE-2026-34459

    Post summary

    The post merely references CVE‑2026‑34459 and the affected component, without providing actionable details such as PoC, exploit code, or mitigation information.

    00010145
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34459 Sandbox Escape via Information Leak and Stack Buffer Overflow in Sandboxie-Plus 1.17.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34459

    Post summary

    The text announces CVE-2026-34459, describing a sandbox escape vulnerability involving information leak and stack buffer overflow in Sandboxie-Plus 1.17.2, with a reference link, but does not provide exploitation tools, PoC, patches, or active exploitation evidence.

    0000041
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34459 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave … https://www.cve.org/CVERecord?id=CVE-2026-34459 ----- Traducción: CVE-2026-34459 San… http://infoflow.cloud`

    Post summary

    The post briefly notes the existence of CVE-2026-34459 for Sandboxie‑Plus and links to the CVE record, but provides no technical depth, proof‑of‑concept, exploit, or mitigation details.

    0000034
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsandboxie-plussandboxie---

Explore more