What is CVE-2017-8360 and why is it significant?
CVE-2017-8360 is a vulnerability in HP's Conexant audio driver that embeds a keylogger via the executables MicTray.exe (32-bit) and MicTray64.exe (64-bit). Discovered by Modzero in May 2017, it records all keystrokes by default, posing a severe privacy risk. The keylogger is particularly dangerous because it runs with a legitimate digital signature, making it hard to detect. For a full technical breakdown, see the Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation.
CVE-2017-8360HP keyloggerConexant audio driverMicTray.exedigital signature