CVE-2017-8360
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.0.46 |
| Running on/with | Platform Versions |
|---|---|
Hp Elite X2 1012 G1 | All versions |
Hp Elitebook 1030 G1 | All versions |
Hp Elitebook 725 G3 | All versions |
Hp Elitebook 745 G3 | All versions |
Hp Elitebook 755 G3 | All versions |
Hp Elitebook 820 G3 | All versions |
Hp Elitebook 828 G3 | All versions |
Hp Elitebook 840 G3 | All versions |
Hp Elitebook 848 G3 | All versions |
Hp Elitebook 850 G3 | All versions |
Hp Elitebook Folio 1040 G3 | All versions |
Hp Elitebook Folio G1 | All versions |
Hp Probook 430 G3 | All versions |
Hp Probook 440 G3 | All versions |
Hp Probook 446 G3 | All versions |
Hp Probook 450 G3 | All versions |
Hp Probook 455 G3 | All versions |
Hp Probook 470 G3 | All versions |
Hp Probook 640 G2 | All versions |
Hp Probook 645 G2 | All versions |
Hp Probook 650 G2 | All versions |
Hp Probook 655 G2 | All versions |
Hp Zbook 15 G3 | All versions |
Hp Zbook 15u G3 | All versions |
Hp Zbook 17 G3 | All versions |
Hp Zbook Studio G3 | All versions |
Microsoft Windows 10 | All versions |
Microsoft Windows 7 | All versions |
References (6)
Source: cve@mitre.org
Source: cve@mitre.org
ExploitMitigationTechnical DescriptionThird Party Advisory
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.