Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Sandboxie-Plus Sandboxie
cpe:2.3:a:sandboxie-plus:sandboxie:5.30:*:*:*:classic:*:*:*
|
— | — |