Lucene search

K
cveMitreCVE-2007-0161
HistoryJan 10, 2007 - 12:28 a.m.

CVE-2007-0161

2007-01-1000:28:00
mitre
web.nvd.nist.gov
23
hp
all-in-one
drivers
cve-2007-0161
privilege escalation
arbitrary program execution

CVSS2

4.1

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

32.5%

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

Affected configurations

Nvd
Node
hppml_driver_hpz12
Node
hpcolor_laserjet_4650
OR
hpofficejet_4100
OR
hpofficejet_5100
OR
hpofficejet_5500
OR
hpofficejet_6100
OR
hpofficejet_7100
OR
hpofficejet_d
OR
hpofficejet_g
OR
hpofficejet_k
OR
hppsc_1100
OR
hppsc_1200
OR
hppsc_1210_all-in-one
OR
hppsc_1300
OR
hppsc_2100
OR
hppsc_2200
OR
hppsc_2400_photosmart_all-in-one
OR
hppsc_2500_photosmart_all-in-one
OR
hppsc_2510_photosmart
OR
hppsc_700
OR
hppsc_900
VendorProductVersionCPE
hppml_driver_hpz12*cpe:2.3:a:hp:pml_driver_hpz12:*:*:*:*:*:*:*:*
hpcolor_laserjet_4650*cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:*
hpofficejet_4100*cpe:2.3:h:hp:officejet_4100:*:*:*:*:*:*:*:*
hpofficejet_5100*cpe:2.3:h:hp:officejet_5100:*:*:*:*:*:*:*:*
hpofficejet_5500*cpe:2.3:h:hp:officejet_5500:*:*:*:*:*:*:*:*
hpofficejet_6100*cpe:2.3:h:hp:officejet_6100:*:*:*:*:*:*:*:*
hpofficejet_7100*cpe:2.3:h:hp:officejet_7100:*:*:*:*:*:*:*:*
hpofficejet_d*cpe:2.3:h:hp:officejet_d:*:*:*:*:*:*:*:*
hpofficejet_g*cpe:2.3:h:hp:officejet_g:*:*:*:*:*:*:*:*
hpofficejet_k*cpe:2.3:h:hp:officejet_k:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS2

4.1

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

32.5%