[News] 0 day discovered in Sandboxie

Status
Not open for further replies.

Aura

Level 20
Thread author
Verified
Jul 29, 2014
966
2,474
1,869
Hey guys Aura here,

I was just wondering if you were aware that there's a 0-day in every version of Sandboxie right now. As it been reported it already or not ? If not, I'll add more information to it. If it is, just close this thread please.

It's a 0-day that have been discovered by one of my friend on HF. He reported it to Sandboxie but didn't get a reply for it yet. He made 2-3 videos showing it and even Teamviewed into one of my Windows 7 Professional SP1 64-bits VM to show me it and it worked flawlessly.

What do you think ?
 
You mean the changes bleeding out of Sandboxie?
 
I saw a malware which displays windows outside the sandbox. It was uploaded in one of the packs.

Yes this one.
You can bypass Sandboxie and open a command prompt console (or any other programs I guess) outside of the Sandboxie environment, with Admin Rights too. IcYSeptember reported it on HF, I can link the thread or quote it here if needed for more information as well as link the videos (Youtube) ?
 
Yes this one.
You can bypass Sandboxie and open a command prompt console (or any other programs I guess) outside of the Sandboxie environment, with Admin Rights too. IcYSeptember reported it on HF, I can link the thread or quote it here if needed for more information as well as link the videos (Youtube) ?
Can you send me the thread link in a PM ?
 
Sbie with default setting let the process run but contain the changes to the system.

@Aura : what you mean by "a zero day in every version" , more details will be appreciated ^^
 
Sbie with default setting let the process run but contain the changes to the system.

@Aura : what you mean by "a zero day in every version" , more details will be appreciated ^^

Apparently, this vulnerability is present in the latest version of Sandboxie (that IcY used) and applies in all the ones prior to it.
He managed to create files directly on my desktop, not the desktop inside Sandboxie.

Can you PM me the link too @Aura ?

Yeah sure give me a few seconds.
 
  • Like
Reactions: WinXPert
M!- if you find the sample discussed please let me know in which pack to find it.
 
I'm talking about different sample, it bypasses Sandboxie too.

IcY didn't even use a sample. He found the 0day himself while trying multiple commands in CMD to see what would happen.
 
Status
Not open for further replies.

You may also like...