Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 109 bronnen 3 kritiek 22 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2017-8360

MEDIUM · 5.5 CVSS Gepubliceerd: CWE-200

Beschrijving NL

Conexant Systems mictray64-taak, zoals gebruikt op HP Elite-, EliteBook-, ProBook- en ZBook-systemen, lekt gevoelige gegevens (toetsaanslagen) naar elk proces. In mictray64.exe (microfoonvakpictogram) 1.0.0.46 wordt een LowLevelKeyboardProc Windows-haak gebruikt om toetsaanslagen vast te leggen. Deze gegevens worden gelekt via onbedoelde kanalen: foutopsporingsberichten die toegankelijk zijn voor elk proces dat in de huidige gebruikerssessie wordt uitgevoerd, en bestandssysteemtoegang tot C:UsersPublicMicTray.log via elk proces.

Origineel (Engels) tonen

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:UsersPublicMicTray.log by any process.

Vendors

Conexant Hp Microsoft

Affected products

Mictray64 Elite X2 1012 G1 Elitebook 1030 G1 Elitebook 725 G3 Elitebook 745 G3 Elitebook 755 G3 Elitebook 820 G3 Elitebook 828 G3 Elitebook 840 G3 Elitebook 848 G3 Elitebook 850 G3 Elitebook Folio 1040 G3 Elitebook Folio G1 Probook 430 G3 Probook 440 G3 Probook 446 G3 Probook 450 G3 Probook 455 G3 Probook 470 G3 Probook 640 G2 Probook 645 G2 Probook 650 G2 Probook 655 G2 Zbook 15 G3 Zbook 15u G3 Zbook 17 G3 Zbook Studio G3 Windows 10 Windows 7

References