CVE List

CVE-2024-58315

Critical 8.4

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

Published December 30, 2025.

Affected software

Get alerts for Tosi Tosibox Key

Reference links