The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2007-01-09 16:28
Updated : 2018-10-16 09:31
NVD link : CVE-2007-0161
Mitre link : CVE-2007-0161
JSON object : View
CWE
Products Affected
hp
- psc_700
- psc_2400_photosmart_all-in-one
- officejet_5500
- psc_1300
- color_laserjet_4650
- officejet_6100
- officejet_g
- officejet_d
- psc_1210_all-in-one
- pml_driver_hpz12
- officejet_5100
- officejet_k
- psc_2200
- officejet_4100
- psc_1200
- psc_1100
- psc_900
- psc_2510_photosmart
- psc_2500_photosmart_all-in-one
- psc_2100
- officejet_7100