PT-2007-1645 · Hewlett Packard · Hp All-In-One Drivers+1
Publicado
2007-01-10
·
Atualizado
2018-10-16
·
CVE-2007-0161
CVSS v2.0
4.1
Média
| Vetor | AV:L/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP all-in-one drivers (affected versions not specified)
Description
The issue concerns the PML Driver HPZ12, specifically the HPZipm12.exe file, which has insecure SERVICE CHANGE CONFIG DACL permissions. This allows local users to gain privileges and execute arbitrary programs. For example, this can be achieved by modifying the
binpath argument.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp All-In-One Drivers
Hpzipm12.Exe