MEDIUM · 5.5

CVE-2017-8360

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyb...

Vulnerability Description

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ConexantMictray64<= 1.0.0.46
HpElite X2 1012 G1-
HpElitebook 1030 G1-
HpElitebook 725 G3-
HpElitebook 745 G3-
HpElitebook 755 G3-
HpElitebook 820 G3-
HpElitebook 828 G3-
HpElitebook 840 G3-
HpElitebook 848 G3-
HpElitebook 850 G3-
HpElitebook Folio 1040 G3-
HpElitebook Folio G1-
HpProbook 430 G3-
HpProbook 440 G3-
HpProbook 446 G3-
HpProbook 450 G3-
HpProbook 455 G3-
HpProbook 470 G3-
HpProbook 640 G2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-8360?

CVE-2017-8360 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyb...

How severe is CVE-2017-8360?

CVE-2017-8360 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-8360?

Check the references section above for vendor advisories and patch information. Affected products include: Conexant Mictray64, Hp Elite X2 1012 G1, Hp Elitebook 1030 G1, Hp Elitebook 725 G3, Hp Elitebook 745 G3.