Skip to content

Commit

Permalink
Update SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
DavidXanatos authored Nov 28, 2024
1 parent 1f24807 commit 1fc8191
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,12 @@ Please report any found security vulnerability directly to me at xanatosdavid[at

## Fixed security issues

### SECURITY ISSUE ID-23
Files storred inside a sandbox folder were accessible to all users on a system,
resulting in security issues in multi user scenarios see [CVE-2024-49360](https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-4chj-3c28-gvmp)

fixed in: 1.15.0 / 5.70.0

### SECURITY ISSUE ID-23 (thanks Diversenok)
A sandboxed process with administrative privileges could enable SeManageVolumePrivilege, this allowed it to read MFT data, in case of files smaller than 1 cluster that allowed to read the file payload

Expand Down

0 comments on commit 1fc8191

Please sign in to comment.