The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2007-01-10 00:28
Updated : 2025-04-09 00:30
NVD link : CVE-2007-0161
Mitre link : CVE-2007-0161
CVE.ORG link : CVE-2007-0161
JSON object : View
Products Affected
hp
- officejet_g
- psc_1300
- psc_2200
- psc_1200
- psc_2500_photosmart_all-in-one
- officejet_4100
- pml_driver_hpz12
- officejet_5500
- officejet_5100
- officejet_k
- officejet_7100
- psc_1210_all-in-one
- psc_2400_photosmart_all-in-one
- officejet_6100
- psc_700
- psc_900
- color_laserjet_4650
- psc_1100
- psc_2100
- officejet_d
- psc_2510_photosmart
CWE