Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47883. PoCs published by Mohammed Alshehri.
AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in Sandboxie Plus v0.7.2. The vulnerability could allow local privilege escalation by exploiting the service path if an executable is planted in a higher directory level.
Description
Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the SbieSvc service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup.
Exploits (1)
This is a writeup describing an unquoted service path vulnerability in Sandboxie Plus v0.7.2. The vulnerability could allow local privilege escalation by exploiting the service path if an executable is planted in a higher directory level.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H