Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8360


Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.


Published

2017-05-12T07:29:00.187

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application conexant mictray64 ≤ 1.0.0.46 Yes
Hardware hp elite_x2_1012_g1 - No
Hardware hp elitebook_1030_g1 - No
Hardware hp elitebook_725_g3 - No
Hardware hp elitebook_745_g3 - No
Hardware hp elitebook_755_g3 - No
Hardware hp elitebook_820_g3 - No
Hardware hp elitebook_828_g3 - No
Hardware hp elitebook_840_g3 - No
Hardware hp elitebook_848_g3 - No
Hardware hp elitebook_850_g3 - No
Hardware hp elitebook_folio_1040_g3 - No
Hardware hp elitebook_folio_g1 - No
Hardware hp probook_430_g3 - No
Hardware hp probook_440_g3 - No
Hardware hp probook_446_g3 - No
Hardware hp probook_450_g3 - No
Hardware hp probook_455_g3 - No
Hardware hp probook_470_g3 - No
Hardware hp probook_640_g2 - No
Hardware hp probook_645_g2 - No
Hardware hp probook_650_g2 - No
Hardware hp probook_655_g2 - No
Hardware hp zbook_15_g3 - No
Hardware hp zbook_15u_g3 - No
Hardware hp zbook_17_g3 - No
Hardware hp zbook_studio_g3 - No
Operating System microsoft windows_10 * No
Operating System microsoft windows_7 * No

References