4.6
CVSSv2

CVE-2003-1169

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

Vulnerable Product Search on Vulmon Subscribe to Product

datev nutzungskontrolle 2.1

datev nutzungskontrolle 2.2

Exploits

source: wwwsecurityfocuscom/bid/8950/info It has been reported that DATEV Nutzungskontrolle may be prone to a access validation issue that may allow a local attacker to gain access to sensitive data The issue presents itself as a local user is able modify certain keys in the Windows registry resulting in bypassing the security model of t ...