Junglewise Threat Intelligence

CVE-2024-58315: Tosibox Key Service unquoted service path privilege escalation

CVE-2024-58315 · Severity: high · CVSS 7.8 · Published 2025-12-30

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Tosibox Key Service 3.3.0, used for secure remote access to operational technology infrastructure, contains a vulnerability in how Windows services are registered. An unprivileged local attacker can exploit this by placing malicious executable code in system directories that are searched during service startup, gaining the ability to execute code with elevated system privileges when the service starts or the system reboots.

Technical details

The vulnerability is an unquoted service path issue in the Windows service registration for Tosibox Key Service 3.3.0. The service executable path is not properly quoted in the Windows registry, allowing an attacker with local access to place a malicious executable in a parent directory of the service path. When the service starts, Windows searches multiple paths to locate the executable, and the malicious code is executed with the service's elevated privileges. The attack requires local network access and does not require elevated privileges to execute the initial attack, though it grants system-level code execution upon service restart. No patch availability information is provided in the advisory.

Affected products

  • Tosibox Key Service 3.3.0

Timeline

  • 2025-12-30: disclosed

References

Related threats