solution Contentsolution Content

支援通訊- SECURITY BULLETIN

文件 ID: c05519670

版本: 9

HPSBGN03558 rev.9 - Conexant HD Audio Driver Local Debug Log

注意: 此 Security Bulletin 內的資訊必須盡快付諸實行。

發行日期 : 12-May-2017

上次更新日期 : 13-Dec-2017

潛在安全性影響:
Potential, local loss of confidentiality

弱點摘要
A potential security vulnerability caused by a local debugging capability that was not disabled prior to product launch has been identified with certain versions of Conexant HD Audio Drivers on HP products. HP has no access to customer data as a result of this issue.
參考編號
CVE TBD, PSR-2017-0067
獲支援軟件版本*: 僅列出受影響版本。
See the RESOLUTION section for impacted products.
背景
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE TBD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
6.5
Information on CVSS is documented in HP Customer Notice: HPSN­2008­002.
解決方案
HP has provided software updates for Conexant HD Audio Driver. Impacted HP products are shown in the table below. We will update the table as SoftPaqs become available.
Please refer to Customer Advisory Advisory: HP Desktops, Notebooks, Mobile Workstations, and Mobile Thin Clients - Conexant HD Audio Driver Local Debug Log for a list of non-vulnerable versions of the MicTray.exe application.
注意:
Versions in the Fixed Vendor Version(s) column denote the minimum version that contains the fix. All subsequent updates will also contain the fix.
Commercial Notebooks
Product Name
SoftPaq Bundle Version(s)
SoftPaq #
Fixed Vendor Version(s)
HP Elite x2 1012 G1
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 725 G3
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP EliteBook 725 G4
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP EliteBook 745 G3
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP EliteBook 745 G4
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP EliteBook 755 G3
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP EliteBook 755 G4
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP EliteBook 820 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 820 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP EliteBook 828 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 828 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP EliteBook 840 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 840 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP EliteBook 848 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 848 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP EliteBook 850 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook 850 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP EliteBook Folio 1030 G1
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook Folio 1040 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook Folio G1
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP EliteBook x360 1030 G2
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP mt20 Mobile Thin Client
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP mt42 Mobile Thin Client
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP mt43 Mobile Thin Client
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP Pro X2 612 G2
11.39.2168.58, Q,53
Windows 10: 9.0.137.1
Windows 7: 8.65.207.1
HP ProBook 11 G2
9.0.134.1, A,10
9.0.134.1
HP ProBook 430 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 430 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 440 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 440 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 446 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 450 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 450 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 455 G3
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP ProBook 455 G4
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP ProBook 470 G3
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 470 G4
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 640 G2
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 640 G3
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 645 G2
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP ProBook 645 G3
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP ProBook 650 G2
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ProBook 650 G3
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ProBook 655 G2
10.0.931.90, Q,52
Windows 10: 8.65.204.1
Windows 8.1: 8.65.204.1
Windows 7: 8.65.204.1
HP ProBook 655 G3
11.39.2168.57, Q,53
Windows 10: 8.65.205.1
Windows 7: 8.65.205.1
HP ProBook x360 11 G1 EE
8.65.211.51, A,14
8.65.211.51
HP Spectre Pro 13 G1
8.65.170.1 A,37
8.65.170.1
HP ZBook 15 G3 Mobile Workstation
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ZBook 15 G4 Mobile Workstation
11.44.2168.60, Q,53
Windows 10: 9.0.139.1
Windows 7: 8.65.208.51
HP ZBook 15u G3 Mobile Workstation
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ZBook 15u G4 Mobile Workstation
11.39.2168.57, Q,53
Windows 10: 9.0.136.1
Windows 7: 8.65.205.1
HP ZBook 17 G3 Mobile Workstation
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ZBook 17 G4 Mobile Workstation
11.44.2168.60, Q,53
Windows 10: 9.0.139.1
Windows 7: 8.65.208.51
HP ZBook Studio G3 Mobile Workstation
10.0.931.90, Q,52
Windows 10: 9.0.134.1
Windows 8.1: 9.0.134.1
Windows 7: 8.65.204.1
HP ZBook Studio G4 Mobile Workstation
11.44.2168.60, Q,53
Windows 10: 9.0.139.1
Windows 7: 8.65.208.51
Commercial Desktops
Product Name
Fixed Version(s)
SoftPaq #
HP Elite Slice (Win 7)
8.65.166.1, A,1
HP Elite Slice (Win10)
8.65.198.1, A,1
HP EliteDesk 800 35W G3 Desktop Mini PC
8.65.186.51, A,1
HP EliteDesk 800 65W G3 Desktop Mini PC
8.65.186.51, A,1
HP EliteDesk 800 G3 Small Form Factor PC
8.65.186.51, A,1 
HP EliteDesk 800 G3 Tower PC
8.65.186.51, A,1
HP EliteDesk 880 G3 Tower PC
8.65.186.51, A,1
HP EliteOne 705 G2 23-inch All-in-One PC
8.65.186.3, B,1
HP EliteOne 800 G2 23-inch Non-Touch All-in-One PC
8.65.186.3, B,1
HP EliteOne 800 G2 23-inch Touch All-in-One PC
8.65.186.3, B,1
HP EliteOne 800 G3 23.8-inch Non-Touch All-in-One PC
8.65.186.1, B,1
HP EliteOne 800 G3 23.8-inch Touch All-in-One PC
8.65.186.1, B,1
HP ProDesk 400 G3 Desktop Mini PC
8.65.186.51, A,1
HP ProDesk 400 G4 Microtower PC
8.65.186.51, A,1
HP ProDesk 400 G4 Small Form Factor PC
8.65.186.51, A,1
HP ProDesk 480 G4 Microtower PC
8.65.186.51, A,1
HP ProDesk 600 G3 Desktop Mini PC
8.65.186.51, A,1
HP ProDesk 600 G3 Microtower PC
8.65.186.51, A,1
HP ProDesk 600 G3 Small Form Factor PC
8.65.186.51, A,1
HP ProDesk 680 G3 Microtower PC
8.65.186.51, A,1 
HP ProOne 600 G2 21.5-inch All-in-One PC
8.65.186.3, B,1 
HP RP9 G1 Retail System Model 9015
8.65.186.3, B,1 
HP RP9 G1 Retail System Model 9018
8.65.186.3, B,1 
Consumer Notebooks
Product Name
Fixed Version(s)
SoftPaq #
HP ENVY Notebook 15-as000-as099
8.65.169.1.A.46
HP ENVY Notebook 15t-as00
8.65.169.1.A.46
HP ENVY Notebook m1-u100-u199
9.0.134.1.A.47
HP ENVY Notebook 17-u100-u199
9.0.134.1.A.47
HP ENVY Notebook 17t-u000
9.0.134.1.A.47
HP ENVY Notebook 15-as100-as199
9.0.134.1.A.47
HP ENVY Notebook 15t-as100
9.0.134.1.A.47
HP ENVY x360 m6-ar0xx
8.65.176.1.F.5
HP ENVY x360 15-ar0xx
8.65.176.1.F.5
HP ENVY x360 m6-aq0xx
8.65.165.11.A.2
HP ENVY x360 15-aq0xx
8.65.165.11.A.2
HP ENVY x360 m6-aq1xx
8.65.203.1.F.3
HP ENVY x360 15-aq1xx
8.65.203.1.F.3
HP Spectre 13-v000 ~ 13-v099
8.65.170.1 A,37
HP Spectre 13-v100 ~ 13-v199
9.0.134.1 A,38
HP Spectre Pro 13 G1
8.65.170.1 A,37
HP ENVY x360 13-y0xx
9.0.140.1.C.6
HP Spectre x360 15-ap000-15ap099
8.65.129.61
HP Spectre x2 12-a000~a099
8.65.133.53
HP Spectre x360 13-4100 ~ 4199
8.65.127.51
HP Spectre x360 13-4100 ~ 4199
9.0.68.61
HP Spectre x360  13-4200 ~ 4299
9.0.68.61
HP Spectre Pro x360 G2
9.0.68.61
HP ENVY Notebook m1-u000 - u099
8.65.142.51.A.50
HP ENVY Notebook 17-u000 ~ 17-u099
8.65.142.51.A.50
HP ENVY Notebook 17t-u000 (CTO)
8.65.142.51.A.50
...
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send an e-mail to hp-security-alert@hp.com.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp­security­alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email, visit https://h41369.www4.hp.com/alerts-signup.php?lang=en&cc=US&jumpid=hpsc_profile.
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
ST
HP Storage Software
GN
HP General Software
Support: For further information, contact normal HP Services support channel.
Report: To report a potential security vulnerability with any HP supported product, send Email to: hp-security-alert@hp.com.
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
您必須時常檢視系統管理及安全措施,以維持系統穩定。為了提供客戶最新、最安全的解決方案,HP 將會持續檢視並加強軟體產品的安全性。

"我們亦將廣為流傳此 Security Bulletin,以使受影響的 HP 產品用戶更加注意本文所列的重要保安資訊。 HP 建議所有用戶自行根據實際情況判斷這些資訊的適用性,並且採取適當的措施。 HP 並不保證這些資訊的精確性及完整性適用於所有用戶,因此 HP 對於用戶因採用或忽視本文件內的資訊而造成的損害概不負責。 在相關法律所允許之最大範圍內,HP 不承擔任何瑕疵責任擔保,不論其為明示或默示者,其中包括適售性、適合某特定用途以及不侵害他人權益之擔保責任。"
修訂歷程記錄 : 11 May 2017: Initial release; 15 May 2017: Updated tables with more softpaqs. Fixed spelling errors. Corrected 2 product names; 16 May 2017: Updated SP80325 to SP80336 - fixing broken link due to superceded executable. Added column of fixed vendor version numbers by OS to commercial notebook table; 7 Nov 2017: Added note regarding subsequent updates. 13 Dec 2017: Updated the HP mt42 Mobile Thin Clientrow in the Commercial Notebooks table per KF ticket 12720.

HP Inc. 對於本文件在技術上或編輯上的錯誤或疏漏概不負責。 本資訊以「維持現狀」的形式提供,不作任何類型的保證。 在法律許可情況下,不論 HP 或其附屬公司、承包商或供應商對於偶然的、特殊的或引發的損害 (包括停工成本;利益損失;採購替代產品或服務之相關損害;或是資料遺失或軟體重建之損害) 概不負責。 本文所載資訊得隨時更改且不另行通知。 本文所述之 HP Inc. 及 HP 產品名稱為 HP Inc. 在美國及其他國家/地區的商標。 本文所提及之其他產品與公司名稱皆為其個別所有者的商標。