云虫漏洞库

CVE-2024-58315 - Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot. - 漏洞详情

漏洞编号:CVE-2024-58315

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2024-58315

CNNVD 编号:-

厂商/产品:tosi / tosibox_key

影响范围:cpe:2.3:a:tosi:tosibox_key:*:*:*:*:*:*:*:*

CWE:CWE-428

发布/更新时间:2025-12-30 / 2026-08-29

漏洞描述

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

相关链接

相关漏洞

« 返回首页