CVE-2017-8360

Summary

CVECVE-2017-8360
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2017-05-12 07:29:00 UTC
Updated2017-07-08 01:29:00 UTC
DescriptionConexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.

Risk And Classification

Problem Types: CWE-200

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Conexant Mictray64 All All All All
Hardware Hp Elitebook 1030 G1 - All All All
Hardware Hp Elitebook 1030 G1 - All All All
Hardware Hp Elitebook 725 G3 - All All All
Hardware Hp Elitebook 725 G3 - All All All
Hardware Hp Elitebook 745 G3 - All All All
Hardware Hp Elitebook 745 G3 - All All All
Hardware Hp Elitebook 755 G3 - All All All
Hardware Hp Elitebook 755 G3 - All All All
Hardware Hp Elitebook 820 G3 - All All All
Hardware Hp Elitebook 820 G3 - All All All
Hardware Hp Elitebook 828 G3 - All All All
Hardware Hp Elitebook 828 G3 - All All All
Hardware Hp Elitebook 840 G3 - All All All
Hardware Hp Elitebook 840 G3 - All All All
Hardware Hp Elitebook 848 G3 - All All All
Hardware Hp Elitebook 848 G3 - All All All
Hardware Hp Elitebook 850 G3 - All All All
Hardware Hp Elitebook 850 G3 - All All All
Hardware Hp Elitebook Folio 1040 G3 - All All All
Hardware Hp Elitebook Folio 1040 G3 - All All All
Hardware Hp Elitebook Folio G1 - All All All
Hardware Hp Elitebook Folio G1 - All All All
Hardware Hp Elite X2 1012 G1 - All All All
Hardware Hp Elite X2 1012 G1 - All All All
Hardware Hp Probook 430 G3 - All All All
Hardware Hp Probook 430 G3 - All All All
Hardware Hp Probook 440 G3 - All All All
Hardware Hp Probook 440 G3 - All All All
Hardware Hp Probook 446 G3 - All All All
Hardware Hp Probook 446 G3 - All All All
Hardware Hp Probook 450 G3 - All All All
Hardware Hp Probook 450 G3 - All All All
Hardware Hp Probook 455 G3 - All All All
Hardware Hp Probook 455 G3 - All All All
Hardware Hp Probook 470 G3 - All All All
Hardware Hp Probook 470 G3 - All All All
Hardware Hp Probook 640 G2 - All All All
Hardware Hp Probook 640 G2 - All All All
Hardware Hp Probook 645 G2 - All All All
Hardware Hp Probook 645 G2 - All All All
Hardware Hp Probook 650 G2 - All All All
Hardware Hp Probook 650 G2 - All All All
Hardware Hp Probook 655 G2 - All All All
Hardware Hp Probook 655 G2 - All All All
Hardware Hp Zbook 15u G3 - All All All
Hardware Hp Zbook 15u G3 - All All All
Hardware Hp Zbook 15 G3 - All All All
Hardware Hp Zbook 15 G3 - All All All
Hardware Hp Zbook 17 G3 - All All All
Hardware Hp Zbook 17 G3 - All All All
Hardware Hp Zbook Studio G3 - All All All
Hardware Hp Zbook Studio G3 - All All All
Operating System Microsoft Windows 10 All All All All
Operating System Microsoft Windows 10 All All All All
Operating System Microsoft Windows 7 All All All All
Operating System Microsoft Windows 7 All All All All

References

ReferenceSourceLinkTags
www.modzero.ch/advisories/MZ-17-01-Conexant-Keylogger.txt MISC www.modzero.ch Exploit, Mitigation, Technical Description, Third Party Advisory
[EN] Keylogger in Hewlett-Packard Audio Driver | mod%log MISC www.modzero.ch Exploit, Technical Description, Third Party Advisory
HP Computer Conexant HD Audio Driver Debug Keylogger Code Lets Local Users Obtain Keyboard Keystrokes - SecurityTracker SECTRACK www.securitytracker.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report