7.8highHigh

CVE-2024-58315

Tosi Tosibox Key

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.8 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4
8.5
Weakness
CWE-428
Assigned by
disclosure@vulncheck.com

Dates

Published
2025-12-30
Last modified
2026-08-29
Sources
NVD

Affected products

  • Tosi Tosibox Key- 3.3.0
  • Microsoft Windowsall versions

As listed in the NVD configuration data. Not a statement about your estate.

References