CVE-2017-8360 describes a sensitive data leakage vulnerability in the Conexant mictray64 task, present in audio drivers on various HP Elite, EliteBook, ProBook, and ZBook systems. This flaw allows any process running in the current user session to access keystrokes captured by the mictray64.exe application through debug messages and a publicly accessible log file. Rated Medium severity (CVSS 5.5), it requires local access but can lead to high confidentiality impact by exposing user input. While not listed on CISA's KEV catalog and lacking public exploit code, it garnered significant media attention and community discussion upon discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.0.46CPE matchmatch criteria | cpe:2.3:a:conexant:mictray64:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.