CVE-2024-58315
Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-428
- Published
- 2025-12-30
- Last modified
- 2026-08-29
Affected products
- Tosibox Oy Tosibox Key Service
- Tosibox Oy Tosibox Key Service
Weakness type
Related vulnerabilities
- CVE-2022-50935 — FLAME II MODEM USB - Unquoted Service Path
- CVE-2026-25866 — MobaXterm < 26.1 Notepad++ Unquoted Service Path
- CVE-2025-41359 — Multiple vulnerabilities in Small HTTP server by Smallsrv
- CVE-2023-54336 — Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path
- CVE-2023-54331 — Outline 1.6.0 - Unquoted Service Path
- CVE-2022-50938 — CONTPAQi® AdminPAQ 14.0.0 - Unquoted Service Path
- CVE-2022-50933 — Cain & Abel 4.9.56 - Unquoted Service Path
- CVE-2022-50930 — Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path