CVE-2017-8360: Infoleak
Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8360?
CVE-2017-8360 is classified as a high-severity vulnerability due to the potential for sensitive data leakage.
How do I fix CVE-2017-8360?
To fix CVE-2017-8360, update the Conexant mictray64 software to a version higher than 1.0.0.46.
What systems are affected by CVE-2017-8360?
CVE-2017-8360 affects HP's Elite, EliteBook, ProBook, and ZBook systems that use Conexant mictray64 software.
What type of data is leaked in CVE-2017-8360?
CVE-2017-8360 leaks sensitive data including keystrokes captured through the LowLevelKeyboardProc Windows hook.
Is there a known exploit for CVE-2017-8360?
Yes, CVE-2017-8360 has been documented, and there are reports of its exploitation to capture keystrokes.