Description
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
Published: 2007-01-10
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2007-0165 The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
History

No history.

Subscriptions

Hp Color Laserjet 4650 Officejet 4100 Officejet 5100 Officejet 5500 Officejet 6100 Officejet 7100 Officejet D Officejet G Officejet K Pml Driver Hpz12 Psc 1100 Psc 1200 Psc 1210 All-in-one Psc 1300 Psc 2100 Psc 2200 Psc 2400 Photosmart All-in-one Psc 2500 Photosmart All-in-one Psc 2510 Photosmart Psc 700 Psc 900
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T12:12:17.406Z

Reserved: 2007-01-09T00:00:00.000Z

Link: CVE-2007-0161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-01-10T00:28:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-0161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses