CVE Vulnerabilities

CVE-2018-18748

Published: Oct 29, 2018 | Modified: May 17, 2024
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Sandboxie 5.26 allows a Sandbox Escape via an import os statement, followed by os.system(cmd) or os.system(powershell), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the products intended functionality

Affected Software

Name Vendor Start Version End Version
Sandboxie Sandboxie 5.26 (including) 5.26 (including)

References