SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0161

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by…

MEDIUM 4.1EPSS 0.74%

Does this matter?

Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.

Description

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

CVSS 2.0
4.1 MEDIUMAV:L/AC:M/Au:S/C:P/I:P/A:P
EPSS
0.74% probability · 53th percentile
CISA KEV
Not listed
Affected
hp/pml driver hpz12 · hp/color laserjet 4650 · hp/officejet 4100 · hp/officejet 5100 · hp/officejet 5500 · hp/officejet 6100 · hp/officejet 7100 · hp/officejet d · hp/officejet g · hp/officejet k · hp/psc 1100 · hp/psc 1200 · hp/psc 1210 all-in-one · hp/psc 1300 · hp/psc 2100 · hp/psc 2200 · hp/psc 2400 photosmart all-in-one · hp/psc 2500 photosmart all-in-one · hp/psc 2510 photosmart · hp/psc 700 · +1 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.