CVE-2011-5158 describes multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components of DATEV Grundpaket Basis CD23.20. These flaws allow local users to gain privileges by placing a malicious DLL (DVBSKNLANG101.dll or DvZediTermSrvInfo004.dll) in a directory containing specific file types, which is then loaded by the vulnerable applications. The vulnerability carries a critical CVSS score of 9.3, indicating a high severity. While the attack vector is local, the complexity is medium, and successful exploitation could lead to complete compromise of confidentiality, integrity, and availability (C:C/I:C/A:C). There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
cd23.20CPE matchmatch criteria | cpe:2.3:a:datev:grundpaket_basis:cd23.20:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.