CVE-2011-5158: Datev Grundpaket Basis
High severity, CVSS 9.3. EPSS: 2% chance of exploitation in the next 30 days.
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file in the current working directory, as demonstrated by a directory that contains a .dmt, .adl, .c02, .dof, or .jrf file. NOTE: some of these details are obtained from third party information.
Affected products
- Datev Grundpaket Basis: version cd23.20 only
Published 2012-09-07. Last modified 2026-06-16.