CVE-2007-0161 (CNNVD-200701-110)

MEDIUM 有利用代码
中文标题:
HP多个产品PML Driver HPZ12服务本地权限提升漏洞
英文标题:
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, u...
CVSS分数: 4.1
发布时间: 2007-01-10 00:00:00
漏洞类型: 授权问题
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v4
漏洞描述
中文描述:

PML Driver HPZ12服务是很多HP产品(尤其是多合一产品、打印机、扫描仪等)所安装的驱动服务。 PML Driver HPZ12服务在执行权限管理时存在漏洞,本地攻击者可能利用此权限提升自己的权限。 PML Driver HPZ12服务没有设置安全的SERVICE_CHANGE_CONFIG权限。默认下安装该服务时有以下属性: Name: PML Driver HPZ12 Filename: HPZipm12.exe Description: Used by HP Printer/Scanner/Copier printers to prevent Windows from entering hibernation mode. File Location: %System% Service Name: PML Driver HPZ12 Service Display Name: PML Driver HPZ12 由于不安全的DACL,本地非特权用户可以通过发布特制命令获得系统权限。尽管PML驱动服务不是默认安装的,但攻击者可以手动启动并终止该服务。

英文描述:

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

CWE类型:
(暂无数据)
标签:
local windows Sowhat OSVDB-32654
受影响产品
厂商 产品 版本 版本范围 平台 CPE
hp pml_driver_hpz12 * - - cpe:2.3:a:hp:pml_driver_hpz12:*:*:*:*:*:*:*:*
hp color_laserjet_4650 * - - cpe:2.3:h:hp:color_laserjet_4650:*:*:*:*:*:*:*:*
hp officejet_4100 * - - cpe:2.3:h:hp:officejet_4100:*:*:*:*:*:*:*:*
hp officejet_5100 * - - cpe:2.3:h:hp:officejet_5100:*:*:*:*:*:*:*:*
hp officejet_5500 * - - cpe:2.3:h:hp:officejet_5500:*:*:*:*:*:*:*:*
hp officejet_6100 * - - cpe:2.3:h:hp:officejet_6100:*:*:*:*:*:*:*:*
hp officejet_7100 * - - cpe:2.3:h:hp:officejet_7100:*:*:*:*:*:*:*:*
hp officejet_d * - - cpe:2.3:h:hp:officejet_d:*:*:*:*:*:*:*:*
hp officejet_g * - - cpe:2.3:h:hp:officejet_g:*:*:*:*:*:*:*:*
hp officejet_k * - - cpe:2.3:h:hp:officejet_k:*:*:*:*:*:*:*:*
hp psc_1100 * - - cpe:2.3:h:hp:psc_1100:*:*:*:*:*:*:*:*
hp psc_1200 * - - cpe:2.3:h:hp:psc_1200:*:*:*:*:*:*:*:*
hp psc_1210_all-in-one * - - cpe:2.3:h:hp:psc_1210_all-in-one:*:*:*:*:*:*:*:*
hp psc_1300 * - - cpe:2.3:h:hp:psc_1300:*:*:*:*:*:*:*:*
hp psc_2100 * - - cpe:2.3:h:hp:psc_2100:*:*:*:*:*:*:*:*
hp psc_2200 * - - cpe:2.3:h:hp:psc_2200:*:*:*:*:*:*:*:*
hp psc_2400_photosmart_all-in-one * - - cpe:2.3:h:hp:psc_2400_photosmart_all-in-one:*:*:*:*:*:*:*:*
hp psc_2500_photosmart_all-in-one * - - cpe:2.3:h:hp:psc_2500_photosmart_all-in-one:*:*:*:*:*:*:*:*
hp psc_2510_photosmart * - - cpe:2.3:h:hp:psc_2510_photosmart:*:*:*:*:*:*:*:*
hp psc_700 * - - cpe:2.3:h:hp:psc_700:*:*:*:*:*:*:*:*
hp psc_900 * - - cpe:2.3:h:hp:psc_900:*:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
2128 third-party-advisory
cve.org
访问
pml-driver-config-privilege-escalation(31361) vdb-entry
cve.org
访问
23663 third-party-advisory
cve.org
访问
ADV-2007-0094 vdb-entry
cve.org
访问
32654 vdb-entry
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
21935 vdb-entry
cve.org
访问
20070108 HP Multiple Products PML Driver Local Privilege Escalation mailing-list
cve.org
访问
ExploitDB EDB-29403 EXPLOIT
exploitdb
访问
Download Exploit EDB-29403 EXPLOIT
exploitdb
访问
CVE Reference: CVE-2007-0161 ADVISORY
cve.org
访问
CVSS评分详情
4.1
MEDIUM
CVSS向量: AV:L/AC:M/Au:S/C:P/I:P/A:P
CVSS版本: 2.0
机密性
PARTIAL
完整性
PARTIAL
可用性
PARTIAL
时间信息
发布时间:
2007-01-10 00:00:00
修改时间:
2024-08-07 12:12:17
创建时间:
2025-11-11 15:32:40
更新时间:
2026-01-26 02:17:09
利用信息
此漏洞有可利用代码!
利用代码数量: 1
利用来源:
未知
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2007-0161 2025-11-11 15:17:48 2025-11-11 07:32:40
NVD nvd_CVE-2007-0161 2025-11-11 14:52:08 2025-11-11 07:41:26
CNNVD cnnvd_CNNVD-200701-110 2025-11-11 15:08:54 2025-11-11 07:49:13
EXPLOITDB exploitdb_EDB-29403 2025-11-11 15:05:53 2025-11-11 08:24:56
版本与语言
当前版本: v4
主要语言: EN
支持语言:
EN ZH
其他标识符:
:
:
安全公告
暂无安全公告信息
变更历史
v4 EXPLOITDB
2025-11-11 16:24:56
references_count: 8 → 11; tags_count: 0 → 4; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
  • references_count: 8 -> 11
  • tags_count: 0 -> 4
  • data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3 CNNVD
2025-11-11 15:49:13
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-200701-110; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 授权问题
  • cnnvd_id: 未提取 -> CNNVD-200701-110
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:41:26
cvss_score: 未提取 → 4.1; cvss_vector: NOT_EXTRACTED → AV:L/AC:M/Au:S/C:P/I:P/A:P; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 21; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • cvss_score: 未提取 -> 4.1
  • cvss_vector: NOT_EXTRACTED -> AV:L/AC:M/Au:S/C:P/I:P/A:P
  • cvss_version: NOT_EXTRACTED -> 2.0
  • affected_products_count: 0 -> 21
  • data_sources: ['cve'] -> ['cve', 'nvd']