ALPC 再见:CVE-2025-64721 沙箱逃逸——通过 IPC 砸穿堆
depthfirst.com | 漏洞 | 严重 | CVE-2025-64721 | #rce | #vulnerability-research | #windows-security | #sandbox-escape | #heap-overflow | #alpc | #sandboxie | #cve-2025-64721
摘要
CVE-2025-64721 深度分析:Sandboxie 的原始 ALPC IPC 处理缺少边界检查,攻击者可泄露堆数据并制造 4GB 堆破坏,最终在 Windows 上获得 SYSTEM 级代码执行。
- CVSS
- 10
- 发布时间
- 收录时间
Skip to content