PT-2007-1645 · Hewlett Packard · Hp All-In-One Drivers+1

Published

2007-01-10

·

Updated

2018-10-16

·

CVE-2007-0161

CVSS v2.0

4.1

Medium

VectorAV:L/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP all-in-one drivers (affected versions not specified)
Description The issue concerns the PML Driver HPZ12, specifically the HPZipm12.exe file, which has insecure SERVICE CHANGE CONFIG DACL permissions. This allows local users to gain privileges and execute arbitrary programs. For example, this can be achieved by modifying the binpath argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0161

Affected Products

Hp All-In-One Drivers
Hpzipm12.Exe