CVE Feed

    Dashboard / CVE / CVE-2017-8360

    CVE-2017-8360

    Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.

    Published:May 12, 2017
    Last Modified:Apr 20, 2025
    EPS:May 12, 2017
    EPSS Score:0.00216
    CVSS Score:5.5

    Affected Products

    Vendor
    Conexant
    Product
    Mictray64
    Vendor
    Hp
    Product
    Elite X2 1012 G1
    Vendor
    Hp
    Product
    Elitebook 1030 G1
    Vendor
    Hp
    Product
    Elitebook 725 G3
    Vendor
    Hp
    Product
    Elitebook 745 G3
    Vendor
    Hp
    Product
    Elitebook 755 G3
    Vendor
    Hp
    Product
    Elitebook 820 G3
    Vendor
    Hp
    Product
    Elitebook 828 G3
    Vendor
    Hp
    Product
    Elitebook 840 G3
    Vendor
    Hp
    Product
    Elitebook 848 G3
    Vendor
    Hp
    Product
    Elitebook 850 G3
    Vendor
    Hp
    Product
    Elitebook Folio 1040 G3
    Vendor
    Hp
    Product
    Elitebook Folio G1
    Vendor
    Hp
    Product
    Probook 430 G3
    Vendor
    Hp
    Product
    Probook 440 G3
    Vendor
    Hp
    Product
    Probook 446 G3
    Vendor
    Hp
    Product
    Probook 450 G3
    Vendor
    Hp
    Product
    Probook 455 G3
    Vendor
    Hp
    Product
    Probook 470 G3
    Vendor
    Hp
    Product
    Probook 640 G2
    Vendor
    Hp
    Product
    Probook 645 G2
    Vendor
    Hp
    Product
    Probook 650 G2
    Vendor
    Hp
    Product
    Probook 655 G2
    Vendor
    Hp
    Product
    Zbook 15 G3
    Vendor
    Hp
    Product
    Zbook 15u G3
    Vendor
    Hp
    Product
    Zbook 17 G3
    Vendor
    Hp
    Product
    Zbook Studio G3
    Vendor
    Microsoft
    Product
    Windows 10
    Vendor
    Microsoft
    Product
    Windows 7

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High