


Perceptive Security
SOC/SIEM Consultancy

Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the SbieSvc service that allows local attackers to execute code with elevated privileges…
Published:
20 januari 2026 om 23:00:00
Alert date:
21 januari 2026 om 19:12:52
Source:
nvd.nist.gov
Security Tools, Operating Systems
CVE-2021-47883 affects Sandboxie Plus 0.7.2, containing an unquoted service path vulnerability in the SbieSvc service. Local attackers can exploit this flaw to execute malicious code with elevated privileges. The vulnerability allows injection of malicious executables into the unquoted binary path. These malicious files will be launched with LocalSystem permissions during service startup. This represents a privilege escalation vulnerability that could lead to complete system compromise by local attackers.
Technical details
Mitigation steps:
Affected products:
Sandboxie Plus
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2021-47883
https://sandboxie-plus.com/
https://www.exploit-db.com/exploits/49631
https://www.vulncheck.com/advisories/sandboxie-plus-sbiesvc-unquoted-service-path
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
