The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 00:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/32654 - | |
References | () http://secunia.com/advisories/23663 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/2128 - | |
References | () http://secway.org/advisory/AD20070108.txt - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/456259/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/21935 - Exploit | |
References | () http://www.vupen.com/english/advisories/2007/0094 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/31361 - |
Information
Published : 2007-01-10 00:28
Updated : 2025-04-09 00:30
NVD link : CVE-2007-0161
Mitre link : CVE-2007-0161
CVE.ORG link : CVE-2007-0161
JSON object : View
Products Affected
hp
- color_laserjet_4650
- psc_1300
- pml_driver_hpz12
- psc_700
- psc_2100
- psc_2200
- psc_2400_photosmart_all-in-one
- officejet_g
- officejet_5500
- psc_1100
- psc_2500_photosmart_all-in-one
- officejet_5100
- officejet_6100
- officejet_d
- officejet_4100
- psc_900
- psc_1200
- psc_2510_photosmart
- psc_1210_all-in-one
- officejet_k
- officejet_7100
CWE