CVE-2003-1169

DATEV Nutzungskontrolle <2.3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1169. PoCs published by t4rku5.

AI-analyzed exploit summary This exploit describes a local registry modification vulnerability in DATEV Nutzungskontrolle, allowing an attacker to bypass security controls by importing specific registry keys. The issue arises from improper access validation on registry keys, enabling unauthorized access to sensitive data.

Description

DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

Exploits (1)

exploitdb WRITEUP VERIFIED
by t4rku5 · textlocalwindows
https://www.exploit-db.com/exploits/23327

This exploit describes a local registry modification vulnerability in DATEV Nutzungskontrolle, allowing an attacker to bypass security controls by importing specific registry keys. The issue arises from improper access validation on registry keys, enabling unauthorized access to sensitive data.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: DATEV Nutzungskontrolle V.2.1 and V.2.2
Auth required
Prerequisites: Local access to the target system · Ability to modify registry keys
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13589
Exploit, Patch mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-November/013113.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8950

Scores

EPSS 0.0082
EPSS Percentile 53.4%

Details

Status published
Products (2)
datev/nutzungskontrolle 2.1
datev/nutzungskontrolle 2.2
Published Dec 31, 2003
Tracked Since Feb 18, 2026