HP Printer Privilege Escalation (CVE-2007-0161)

medium Tenable OT Security Plugin ID 505342

Synopsis

The remote OT asset is affected by a vulnerability.

Description

The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://securityreason.com/securityalert/2128

https://exchange.xforce.ibmcloud.com/vulnerabilities/31361

Plugin Details

Severity: Medium

ID: 505342

File Name: tenable_ot_hp_CVE-2007-0161.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 4/30/2026

Updated: 4/30/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: Medium

Base Score: 4.1

Vector: CVSS2#AV:L/AC:M/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2007-0161

Vulnerability Information

CPE: cpe:/h:hp:color_laserjet_4650

Required KB Items: Tenable.ot/HP

Patch Publication Date: 1/10/2007

Vulnerability Publication Date: 1/10/2007

Reference Information

CVE: CVE-2007-0161