CVE-2007-0161

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hp:pml_driver_hpz12:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_4100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_5100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_5500:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_6100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_7100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_d:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_g:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_k:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1200:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1210_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1300:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2200:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2400_photosmart_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2500_photosmart_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2510_photosmart:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_700:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_900:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://osvdb.org/32654 - () http://osvdb.org/32654 -
References () http://secunia.com/advisories/23663 - Vendor Advisory () http://secunia.com/advisories/23663 - Vendor Advisory
References () http://securityreason.com/securityalert/2128 - () http://securityreason.com/securityalert/2128 -
References () http://secway.org/advisory/AD20070108.txt - Vendor Advisory () http://secway.org/advisory/AD20070108.txt - Vendor Advisory
References () http://www.securityfocus.com/archive/1/456259/100/0/threaded - () http://www.securityfocus.com/archive/1/456259/100/0/threaded -
References () http://www.securityfocus.com/bid/21935 - Exploit () http://www.securityfocus.com/bid/21935 - Exploit
References () http://www.vupen.com/english/advisories/2007/0094 - () http://www.vupen.com/english/advisories/2007/0094 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/31361 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/31361 -

Information

Published : 2007-01-10 00:28

Updated : 2025-04-09 00:30


NVD link : CVE-2007-0161

Mitre link : CVE-2007-0161

CVE.ORG link : CVE-2007-0161


JSON object : View

Products Affected

hp

  • color_laserjet_4650
  • psc_1300
  • pml_driver_hpz12
  • psc_700
  • psc_2100
  • psc_2200
  • psc_2400_photosmart_all-in-one
  • officejet_g
  • officejet_5500
  • psc_1100
  • psc_2500_photosmart_all-in-one
  • officejet_5100
  • officejet_6100
  • officejet_d
  • officejet_4100
  • psc_900
  • psc_1200
  • psc_2510_photosmart
  • psc_1210_all-in-one
  • officejet_k
  • officejet_7100