CVE-2007-0161

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hp:pml_driver_hpz12:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_4100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_5100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_5500:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_6100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_7100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_d:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_g:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:officejet_k:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1200:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1210_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_1300:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2100:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2200:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2400_photosmart_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2500_photosmart_all-in-one:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_2510_photosmart:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_700:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:psc_900:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-01-10 00:28

Updated : 2023-12-10 10:40


NVD link : CVE-2007-0161

Mitre link : CVE-2007-0161

CVE.ORG link : CVE-2007-0161


JSON object : View

Products Affected

hp

  • pml_driver_hpz12
  • psc_2200
  • psc_700
  • psc_2100
  • officejet_k
  • psc_2500_photosmart_all-in-one
  • officejet_5500
  • officejet_4100
  • psc_1100
  • psc_2510_photosmart
  • psc_1210_all-in-one
  • psc_1300
  • officejet_6100
  • officejet_7100
  • color_laserjet_4650
  • psc_2400_photosmart_all-in-one
  • officejet_d
  • officejet_5100
  • psc_900
  • officejet_g
  • psc_1200