📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Government HIGH 46m Global malware Software Development CRITICAL 55m Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 46m Global malware Software Development CRITICAL 55m Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 46m Global malware Software Development CRITICAL 55m Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h
Vulnerabilities

CVE-2026-34459

High ⚡ Exploit Available
CWE-121 — Weakness Type
Published: May 5, 2026  ·  Modified: May 12, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that can be chained for sandbox escape. First, when a sandboxed process sends an IPC request with cbSize set to 0, up to 32KB of uninitialized stack memory from the service process is returned, leaking return addresses and stack cookies which bypass ASLR and /GS protections. Second, the handler performs a memcpy with an attacker-controlled length without verifying it fits within the 32KB stack buffer, enabling a stack buffer overflow. By chaining the information leak with the overflow, a sandboxed process can execute a ROP chain to achieve SYSTEM privilege escalation, even from a Security Hardened Sandbox. Hardware-enforced shadow stacks (Intel CET) prevent the ROP chain execution but do not mitigate the information leak. This issue has been fixed in version 1.17.3.

🤖 AI Executive Summary

Sandboxie-Plus versions 1.17.2 and earlier contain two chained vulnerabilities in the SbieSvc proxy service that allow sandbox escape through information disclosure and stack buffer overflow. An attacker can leak stack memory to bypass ASLR/GS protections and execute arbitrary code with SYSTEM privileges.

📄 Description (Arabic)

تحتوي معالج GetRawInputDeviceInfoSlave في خدمة SbieSvc على ثغرتي معلومات وتجاوز مخزن مؤقت يمكن ربطهما معاً. يسمح تسرب الذاكرة بالحصول على عناوين الإرجاع وملفات تعريف الأمان، مما يسمح بتنفيذ سلسلة ROP للحصول على امتيازات SYSTEM حتى من الحماية الرملية المعززة.

🤖 ملخص تنفيذي (AI)

Sandboxie-Plus إصدارات 1.17.2 وأقدم تحتوي على ثغرتين في خدمة SbieSvc تسمح بالهروب من الحماية الرملية عبر تسرب المعلومات وتجاوز المخزن المؤقت. يمكن للمهاجم تسرب ذاكرة المكدس وتنفيذ كود عشوائي بامتيازات SYSTEM.

🤖 AI Intelligence Analysis Analyzed: May 9, 2026 14:22
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking government healthcare telecom
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
9.0
/ 10.0
🔧 Remediation Steps (English)
Upgrade Sandboxie-Plus to version 1.17.3 or later immediately. For organizations unable to upgrade, disable or restrict access to the SbieSvc proxy service and implement network segmentation to limit exposure. Monitor for suspicious IPC requests with cbSize=0 and unusual stack memory access patterns.
🔧 خطوات المعالجة (العربية)
قم بترقية Sandboxie-Plus إلى الإصدار 1.17.3 أو أحدث فوراً. للمنظمات غير القادرة على الترقية، قم بتعطيل أو تقييد الوصول إلى خدمة SbieSvc وتطبيق تقسيم الشبكة. راقب طلبات IPC المريبة وأنماط الوصول غير العادية للذاكرة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.1.1.1 A.2.1.1 A.2.1.2 A.3.1.1
🔵 SAMA CSF
ID.BE-5.1 PR.AC-1.1 PR.AC-1.2 DE.CM-1.1
🟡 ISO 27001:2022
A.5.1.1 A.6.1.1 A.12.2.1 A.12.6.1
📦 Affected Products / CPE 1 entries
sandboxie-plus:sandboxie
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-121
EPSS0.01%
Exploit ✓ Yes
Patch ✗ No
Published 2026-05-05
Source Feed nvd
🇸🇦 Saudi Risk Score
9.0
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-121
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.