CVE-2025-46716

Source
https://cve.org/CVERecord?id=CVE-2025-46716
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46716.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46716
Aliases
  • GHSA-3984-r877-q7xp
Published
2025-05-22T16:50:18.448Z
Modified
2026-04-10T05:28:30.923714Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Sandboxie Arbitrary Kernel Read in SbieDrv.sys API (API_SET_SECURE_PARAM)
Details

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, ApiSetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the pointer the user has passed in is safe to read from. SetRegValue then reads an arbitrary address, which can be a kernel pointer, into a HKLM Security SBIE registry value. This can later be retrieved by APIGETSECUREPARAM. Version 1.15.12 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46716.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/sandboxie-plus/sandboxie

Affected ranges

Type
GIT
Repo
https://github.com/sandboxie-plus/sandboxie
Events

Affected versions

1.*
1.3.4
v1.*
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.12.0
v1.12.1
v1.12.2
v1.12.3
v1.12.4
v1.12.5
v1.12.6
v1.12.7
v1.12.8
v1.12.9
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.13.7
v1.14.0
v1.14.1
v1.14.10
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.14.7
v1.14.8
v1.14.9
v1.15.0
v1.15.1
v1.15.10
v1.15.2
v1.15.3
v1.15.4
v1.15.5
v1.15.6
v1.15.7
v1.15.8
v1.15.9
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.5
v1.4.0
v1.4.1
v1.4.2
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.1a
v1.6.1b
v1.6.2b
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.6.7
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.2a
v1.8.3
v1.8.4
v1.9.0
v1.9.1
v1.9.3
v1.9.4
v1.9.6
v1.9.7
v1.9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46716.json"