First published: Wed Jan 10 2007(Updated: )
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP PML Driver HPZ12 | ||
HP OfficeJet 4100 | ||
HP psc 900 | ||
HP psc 1300 | ||
HP psc 2100 | ||
HP OfficeJet 7100 | ||
HP OfficeJet 5500 | ||
HP OfficeJet 6100 | ||
HP OfficeJet K | ||
HP psc 1100 | ||
HP psc 2400 Photosmart All-in-One | ||
HP psc 2200 | ||
HP psc 2500 Photosmart All-in-One | ||
HP Color LaserJet 4650 | ||
HP OfficeJet 5100 | ||
HP psc 700 | ||
HP OfficeJet D | ||
HP psc 2500 Photosmart All-in-One | ||
HP PSC 1210 All-in-One | ||
HP psc 1200 | ||
HP OfficeJet G |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0161 has been categorized as a high severity vulnerability due to its ability to allow local users to gain elevated privileges.
To remediate CVE-2007-0161, ensure that proper permissions are set for the SERVICE_CHANGE_CONFIG DACL for the HP PML Driver HPZ12.
CVE-2007-0161 affects multiple HP all-in-one printer models that utilize the HP PML Driver HPZ12.
CVE-2007-0161 can be exploited through local privilege escalation, allowing attackers to launch arbitrary programs.
While a complete fix is recommended, a temporary workaround may involve restricting access to the affected service until a patch is applied.