Description
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-0165 | The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023. |
References
History
No history.
Subscriptions
Hp
Subscribe
Color Laserjet 4650
Subscribe
Officejet 4100
Subscribe
Officejet 5100
Subscribe
Officejet 5500
Subscribe
Officejet 6100
Subscribe
Officejet 7100
Subscribe
Officejet D
Subscribe
Officejet G
Subscribe
Officejet K
Subscribe
Pml Driver Hpz12
Subscribe
Psc 1100
Subscribe
Psc 1200
Subscribe
Psc 1210 All-in-one
Subscribe
Psc 1300
Subscribe
Psc 2100
Subscribe
Psc 2200
Subscribe
Psc 2400 Photosmart All-in-one
Subscribe
Psc 2500 Photosmart All-in-one
Subscribe
Psc 2510 Photosmart
Subscribe
Psc 700
Subscribe
Psc 900
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:12:17.406Z
Reserved: 2007-01-09T00:00:00.000Z
Link: CVE-2007-0161
No data.
Status : Modified
Published: 2007-01-10T00:28:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-0161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD