CVE-2024-58315

Executive Summary

Tosibox Key Service 3.3.0 contains an unquoted service path flaw that allows local non‑privileged users to inject code into the system root path. By manipulating the service startup, attackers can execute arbitrary code with elevated system privileges during application launch or reboot, enabling local privilege escalation.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2025-12-30T23:15:48.700 - Last Modified: 2026-08-29T14:16:36.470

Original Description: Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

"I'm a great believer in luck and I find the harder I work, the more I have of it."

— Thomas Jefferson
Source: NVD