Executive brief
Tosibox Key Service 3.3.0, used for secure remote access to operational technology infrastructure, contains a vulnerability in how Windows services are registered. An unprivileged local attacker can exploit this by placing malicious executable code in system directories that are searched during service startup, gaining the ability to execute code with elevated system privileges when the service starts or the system reboots.
Technical details
The vulnerability is an unquoted service path issue in the Windows service registration for Tosibox Key Service 3.3.0. The service executable path is not properly quoted in the Windows registry, allowing an attacker with local access to place a malicious executable in a parent directory of the service path. When the service starts, Windows searches multiple paths to locate the executable, and the malicious code is executed with the service's elevated privileges. The attack requires local network access and does not require elevated privileges to execute the initial attack, though it grants system-level code execution upon service restart. No patch availability information is provided in the advisory.
Affected products
- Tosibox Key Service 3.3.0
Timeline
- 2025-12-30: disclosed