CVE-2022-50920
Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.
- Affected products
- Sandboxie Plus, Windows Service
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 8.4 HIGH
- EPSS
- 0.1% (3th percentile)
- Weakness
- CWE-428
- NVD status
- Deferred
- Published
- 2026-01-13
CVE-2022-50920 at NVD
No indexed exploits for CVE-2022-50920 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-50920 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.