Enabling Windows Sandbox and by extension Hyper-V can allow the use of a zero-day vulnerability, which has been identified in many versions of Windows 10.

An engineer has discovered a new zero-day vulnerability in most versions of Windows 10 that allows files to be created in “restricted” areas of the operating system. The zero-day vulnerability is easy to exploit and attackers can use it to amplify attack after the initial infection of the computer, although it only works on machines with Hyper-V enabled.
Easy acquisition of more privileges on the target computer
engineer Jonas Lykkegaard posted a tweet last week showing how an unauthorized user can create a file in “system32,” a folder that contains vital files for the Windows operating system.
However, as we said above, this can only be done if Hyper-V is enabled, which limits the scope of targets, as the option is disabled by default and is present in Windows 10 Pro, Enterprise, and Education.
Microsoft has added Hyper-V for creating so-called “virtual machines” (VMs) in Windows 10 .
If there are sufficient hardware resources, Hyper-V can run large VMs with 32 processors and 512 GB of RAM. An average user may not be able to run such a VM, but they can run Windows Sandbox, an isolated environment for running programs or loading untrusted websiteswithout the risk of infecting the regular Windows operating system.
Microsoft introduced Windows Sandbox with the May 2019 Update, in Windows 10 version 1903. Enabling Windows Sandbox automatically turns on Hyper-V.

To demonstrate the zero-day vulnerability, Lykkegaard created an empty file named phoneinfo.dll. Making changes to this location requires elevated privileges, but these restrictions do not exist when Hyper-V is enabled.
An attacker can use the vulnerability to insert malicious code into the file.
Vulnerability analyst Will Dormann confirmed that the zero-day vulnerability exists and that exploiting it requires literally no effort from the attacker.
The researcher said that the vulnerable component is “storvsp.sys” (Storage VSP – Virtualization Service Provider), a server-side Hyper-V component.
While this vulnerability can be easily exploited by hackers, there are more serious issues in Windows 10 that Microsoft. That's one reason the engineer decided to make it public rather than report it through Microsoft's bug bounty program.
Lykkegaard has found many bugs. One of the most dangerous allows the management of UEFI applications (Unified Extensible Firmware Interface).
The engineer also said that Microsoft has greatly reduced the reward for reporting critical bugs (from $20,000 to $2,000), which was another reason why he reported the zero-day vulnerability publicly.
“Until now, I have always submitted my findings within the framework of the program and waited until they were corrected, but with the recent change in fees, it is not worth it,” Lykkegaard said.
However, the researcher would still make efforts to find and report such bugs in Windows if Microsoft made a donation to support the education of less fortunate children (for example, giving a laptop to every child in need).
