← Back

CVE-2017-8360

nvd nist
Published: May 12, 2017Modified: May 13, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.

Affected (1)

Products: Conexant: Mictray64
1 product
Mictray64
Configuration A
1 vulnerable · 28 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.0.46
Running on/withPlatform Versions
Hp
Elite X2 1012 G1
All versions
Hp
Elitebook 1030 G1
All versions
Hp
Elitebook 725 G3
All versions
Hp
Elitebook 745 G3
All versions
Hp
Elitebook 755 G3
All versions
Hp
Elitebook 820 G3
All versions
Hp
Elitebook 828 G3
All versions
Hp
Elitebook 840 G3
All versions
Hp
Elitebook 848 G3
All versions
Hp
Elitebook 850 G3
All versions
Hp
Elitebook Folio 1040 G3
All versions
Hp
Elitebook Folio G1
All versions
Hp
Probook 430 G3
All versions
Hp
Probook 440 G3
All versions
Hp
Probook 446 G3
All versions
Hp
Probook 450 G3
All versions
Hp
Probook 455 G3
All versions
Hp
Probook 470 G3
All versions
Hp
Probook 640 G2
All versions
Hp
Probook 645 G2
All versions
Hp
Probook 650 G2
All versions
Hp
Probook 655 G2
All versions
Hp
Zbook 15 G3
All versions
Hp
Zbook 15u G3
All versions
Hp
Zbook 17 G3
All versions
Hp
Zbook Studio G3
All versions
Microsoft
Windows 10
All versions
Microsoft
Windows 7
All versions

References (6)

Source: cve@mitre.org
ExploitMitigationTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory

Timeline

No history available yet.