---
id: CVE-2024-58315
title: >-
  Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that
  allows local non-privileged users to potentially execute code with elevated
  system privileges
summary: >-
  Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that
  allows local non-privileged users to potentially execute code with elevated
  system privileges. Attackers can exploit the service startup process by
  inserting …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
vendor: tosi
product: tosibox_key
affected:
  - tosibox_key <= 3.3.0
published: '2025-12-30'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58315'
references:
  - url: 'https://packetstormsecurity.com/files/177260/'
    label: disclosure@vulncheck.com
  - url: 'https://www.tosi.net/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tosibox-key-service-local-privilege-escalation-via-unquoted-service-path
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5812.php'
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5812.php'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00229
epssPercentile: 0.12247
ingestedAt: '2026-08-29T14:37:53.139Z'
---

## Overview

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

## Affected

- `tosibox_key <= 3.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
