vendor:
Sandboxie Plus
by:
Erick Galindo
8.8
CVSS
HIGH
Unquoted Service Path
N/A
CWE
Product Name: Sandboxie Plus
Affected Version From: 0.7.4
Affected Version To: 0.7.4
Patch Exists: N/A
Related CWE: N/A
CPE: a:sandboxie_plus:sandboxie_plus:0.7.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
Sandboxie Plus 0.7.4 – ‘SbieSvc’ Unquoted Service Path
This vulnerability could permit executing code during startup or reboot with the escalated privileges.
Mitigation:
Ensure that all services have a fully qualified path name.