Sensitive Keystroke Data Leakage in Conexant Systems MicTray64 Task

Sensitive Keystroke Data Leakage in Conexant Systems MicTray64 Task

CVE-2017-8360 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.

Learn more about our User Device Pen Test.