CVE-2007-0161 : Detail

CVE-2007-0161

0.04%V3
Local
2007-01-09
23h00 +00:00
2018-10-16
12h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.1 AV:L/AC:M/Au:S/C:P/I:P/A:P nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 29403

Publication date : 2007-01-07 23h00 +00:00
Author : Sowhat
EDB Verified : Yes

source: https://www.securityfocus.com/bid/21935/info Multiple HP products are prone to a local privilege-escalation vulnerability. An attacker can exploit this issue to gain SYSTEM-level privileges, completely compromising affected computers. This issue affects HP products that use the 'PML Driver HPZ12' driver. C:\sc config "pml driver hpz12" binpath= D:\attack\attack.exe C:\sc start "pml driver hpz12"

Products Mentioned

Configuraton 0

Hp>>Pml_driver_hpz12 >> Version *

Configuraton 0

Hp>>Color_laserjet_4650 >> Version *

Hp>>Officejet_4100 >> Version *

Hp>>Officejet_5100 >> Version *

Hp>>Officejet_5500 >> Version *

Hp>>Officejet_6100 >> Version *

Hp>>Officejet_7100 >> Version *

Hp>>Officejet_d >> Version *

Hp>>Officejet_g >> Version *

Hp>>Officejet_k >> Version *

Hp>>Psc_1100 >> Version *

Hp>>Psc_1200 >> Version *

Hp>>Psc_1210_all-in-one >> Version *

Hp>>Psc_1300 >> Version *

Hp>>Psc_2100 >> Version *

Hp>>Psc_2200 >> Version *

Hp>>Psc_2400_photosmart_all-in-one >> Version *

Hp>>Psc_2500_photosmart_all-in-one >> Version *

Hp>>Psc_2510_photosmart >> Version *

Hp>>Psc_700 >> Version *

Hp>>Psc_900 >> Version *

References

http://securityreason.com/securityalert/2128
Tags : third-party-advisory, x_refsource_SREASON
http://secunia.com/advisories/23663
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.vupen.com/english/advisories/2007/0094
Tags : vdb-entry, x_refsource_VUPEN
http://osvdb.org/32654
Tags : vdb-entry, x_refsource_OSVDB
http://www.securityfocus.com/bid/21935
Tags : vdb-entry, x_refsource_BID