Vulnerabilities > CVE-2007-0161 - Products PML Driver HPZ12 Local Privilege Escalation vulnerability in HP

047910
CVSS 4.1 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
hp
exploit available

Summary

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

Exploit-Db

descriptionHP Multiple Products PML Driver HPZ12 Local Privilege Escalation Vulnerability. CVE-2007-0161. Local exploit for windows platform
idEDB-ID:29403
last seen2016-02-03
modified2007-01-08
published2007-01-08
reporterSowhat
sourcehttps://www.exploit-db.com/download/29403/
titleHP Multiple Products PML Driver HPZ12 - Local Privilege Escalation Vulnerability