CVE-2003-1169

DATEV Nutzungskontrolle <2.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

Exploits (1)

exploitdb WRITEUP VERIFIED
by t4rku5 · textlocalwindows
https://www.exploit-db.com/exploits/23327

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13589
Exploit, Patch mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013113.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8950

Scores

EPSS 0.0031
EPSS Percentile 53.9%

Details

Status published
Products (2)
datev/nutzungskontrolle 2.1
datev/nutzungskontrolle 2.2
Published Dec 31, 2003
Tracked Since Feb 18, 2026