// For flags

CVE-2007-0161

HP (Multiple Products) - PML Driver HPZ12 Privilege Escalation

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

El controlador PML HPZ12 (HPZipm12.exe) en los controladores todo en uno de HP, usado en múltiples productos HP, utiliza permisos no seguros SERVICE_CHANGE_CONFIG DACL, lo cual permite a un usuario local ganar privilegios y ejecutar programas de su elección, como se demostró con la modificación del argumento binpath, un asunto relacionado con CVE-2006-0023.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-01-08 First Exploit
  • 2007-01-09 CVE Reserved
  • 2007-01-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Pml Driver Hpz12
Search vendor "Hp" for product "Pml Driver Hpz12"
*-
Affected
Hp
Search vendor "Hp"
Color Laserjet 4650
Search vendor "Hp" for product "Color Laserjet 4650"
*-
Affected
Hp
Search vendor "Hp"
Officejet 4100
Search vendor "Hp" for product "Officejet 4100"
*-
Affected
Hp
Search vendor "Hp"
Officejet 5100
Search vendor "Hp" for product "Officejet 5100"
*-
Affected
Hp
Search vendor "Hp"
Officejet 5500
Search vendor "Hp" for product "Officejet 5500"
*-
Affected
Hp
Search vendor "Hp"
Officejet 6100
Search vendor "Hp" for product "Officejet 6100"
*-
Affected
Hp
Search vendor "Hp"
Officejet 7100
Search vendor "Hp" for product "Officejet 7100"
*-
Affected
Hp
Search vendor "Hp"
Officejet D
Search vendor "Hp" for product "Officejet D"
*-
Affected
Hp
Search vendor "Hp"
Officejet G
Search vendor "Hp" for product "Officejet G"
*-
Affected
Hp
Search vendor "Hp"
Officejet K
Search vendor "Hp" for product "Officejet K"
*-
Affected
Hp
Search vendor "Hp"
Psc 1100
Search vendor "Hp" for product "Psc 1100"
*-
Affected
Hp
Search vendor "Hp"
Psc 1200
Search vendor "Hp" for product "Psc 1200"
*-
Affected
Hp
Search vendor "Hp"
Psc 1210 All-in-one
Search vendor "Hp" for product "Psc 1210 All-in-one"
*-
Affected
Hp
Search vendor "Hp"
Psc 1300
Search vendor "Hp" for product "Psc 1300"
*-
Affected
Hp
Search vendor "Hp"
Psc 2100
Search vendor "Hp" for product "Psc 2100"
*-
Affected
Hp
Search vendor "Hp"
Psc 2200
Search vendor "Hp" for product "Psc 2200"
*-
Affected
Hp
Search vendor "Hp"
Psc 2400 Photosmart All-in-one
Search vendor "Hp" for product "Psc 2400 Photosmart All-in-one"
*-
Affected
Hp
Search vendor "Hp"
Psc 2500 Photosmart All-in-one
Search vendor "Hp" for product "Psc 2500 Photosmart All-in-one"
*-
Affected
Hp
Search vendor "Hp"
Psc 2510 Photosmart
Search vendor "Hp" for product "Psc 2510 Photosmart"
*-
Affected
Hp
Search vendor "Hp"
Psc 700
Search vendor "Hp" for product "Psc 700"
*-
Affected
Hp
Search vendor "Hp"
Psc 900
Search vendor "Hp" for product "Psc 900"
*-
Affected