vendor:
Sandboxie Plus
by:
Mohammed Alshehri
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Sandboxie Plus
Affected Version From: 2000.7.2
Affected Version To: 2000.7.2
Patch Exists: NO
Related CWE:
CPE: sandboxie-plus:sandboxie_plus:0.7.2
Platforms Tested: Windows
2021
Sandboxie Plus v0.7.2 – ‘SbieSvc’ Unquoted Service Path
This vulnerability could permit executing code during startup or reboot with the escalated privileges.
Mitigation:
Ensure that all service paths are quoted in the Windows registry.