MEDIUM · 4.1

CVE-2007-0161

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and...

Vulnerability Description

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

CVSS Score

4.1

MEDIUM

AV:L/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
HpPml Driver Hpz12All versions
HpColor Laserjet 4650All versions
HpOfficejet 4100All versions
HpOfficejet 5100All versions
HpOfficejet 5500All versions
HpOfficejet 6100All versions
HpOfficejet 7100All versions
HpOfficejet DAll versions
HpOfficejet GAll versions
HpOfficejet KAll versions
HpPsc 1100All versions
HpPsc 1200All versions
HpPsc 1210 All-In-OneAll versions
HpPsc 1300All versions
HpPsc 2100All versions
HpPsc 2200All versions
HpPsc 2400 Photosmart All-In-OneAll versions
HpPsc 2500 Photosmart All-In-OneAll versions
HpPsc 2510 PhotosmartAll versions
HpPsc 700All versions

References

FAQ

What is CVE-2007-0161?

CVE-2007-0161 is a vulnerability with a CVSS score of 4.1 (MEDIUM). The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and...

How severe is CVE-2007-0161?

CVE-2007-0161 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0161?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Pml Driver Hpz12, Hp Color Laserjet 4650, Hp Officejet 4100, Hp Officejet 5100, Hp Officejet 5500.