CVE-2025-54422 Details
Description
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, exposing them to potential interception. The vulnerability is particularly severe during password modification operations, where both old and new passwords are passed as plaintext command-line arguments to the Imbox process without any encryption or obfuscation. This implementation flaw allows any process within the user session, including unprivileged processes, to retrieve these sensitive credentials by reading the command-line arguments, thereby bypassing standard privilege requirements and creating a significant security risk. This is fixed in version 1.16.2.
A critical vulnerability in password handling has been identified in Sandboxie versions 1.16.1 and prior. During the creation of encrypted sandboxes, user passwords are transmitted via shared memory, creating a risk of interception. This issue is exacerbated during password modification, where both old and new passwords are sent as plaintext command-line arguments to the Imbox process, without any encryption or obfuscation. This flaw allows any process within the user session, including those with no special privileges, to access these sensitive passwords by reading the command-line arguments, bypassing standard privilege requirements.
Users can update to Sandboxie version 1.16.2, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
| CWE-322 | Key Exchange without Entity Authentication | [email protected] |
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sandboxie-plus sandboxie | < 1.16.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | New CVE Received | [email protected] |