Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2017.1326 HPSBGN03558 rev.7 - Conexant HD Audio Driver Local Debug Log 24 May 2017 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Conexant HD Audio Driver Publisher: Hewlett-Packard Operating System: Windows Impact/Access: Access Privileged Data -- Existing Account Resolution: Patch/Upgrade CVE Names: PSR-2017-0067 Original Bulletin: https://support.hp.com/us-en/document/c05519670 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Note: the current version of the following document is available here: https://support.hp.com/us-en/document/c05519670 SUPPORT COMMUNICATION- SECURITY BULLETIN Document ID: c05519670 Version: 1 HPSBGN03558 rev.7 - Conexant HD Audio Driver Local Debug Log Notice:: The information in this security bulletin should be acted upon as soon as possible. Release date : 12-May-2017 Last updated : 16-May-2017 Potential Security Impact: Potential, local loss of confidentiality Source:HP, HP Product Security Response Team (PSRT) VULNERABILITY SUMMARY A potential security vulnerability caused by a local debugging capability that was not disabled prior to product launch has been identified with certain versions of Conexant HD Audio Drivers on HP products. HP has no access to customer data as a result of this issue. References: * CVE TBD=20 * PSR-2017-0067 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. See the RESOLUTION section for impacted products. BACKGROUND For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com CVSS 3.0 Base Metrics =========================================================================== Reference Base Vector Base Score CVE TBD CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 6.5 =========================================================================== Information on CVSS is documented in HP Customer Notice: HPSN2008002. RESOLUTION HP has provided software updates for Conexant HD Audio Driver. Impacted HP products are shown in the table below. We will update the table as SoftPaqs become available. Commercial Notebooks Product Name SoftPaq Bundle Version(s) SoftPaq # Fixed Vendor Version(s) HP Elite x2 1012 G1 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 725 G3 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP EliteBook 725 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP EliteBook 745 G3 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP EliteBook 745 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP EliteBook 755 G3 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP EliteBook 755 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP EliteBook 820 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 820 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP EliteBook 828 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 828 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP EliteBook 840 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 840 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP EliteBook 848 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 848 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP EliteBook 850 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook 850 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP EliteBook Folio 1030 G1 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook Folio 1040 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook Folio G1 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP EliteBook x360 1030 G2 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP mt20 Mobile Thin Client 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP mt42 Mobile Thin Client 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP mt43 Mobile Thin Client 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP Pro X2 612 G2 11.39.2168.58, Q,53 SP80321 Windows 10: 9.0.137.1 Windows 7: 8.65.207.1 HP ProBook 11 G2 9.0.134.1, A,10 SP80330 9.0.134.1 HP ProBook 430 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 430 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 440 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 440 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 446 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 450 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 450 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 455 G3 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP ProBook 455 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP ProBook 470 G3 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 470 G4 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 640 G2 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 640 G3 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 645 G2 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP ProBook 645 G3 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP ProBook 650 G2 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ProBook 650 G3 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ProBook 655 G2 10.0.931.90, Q,52 SP80323 Windows 10: 8.65.204.1 Windows 8.1: 8.65.204.1 Windows 7: 8.65.204.1 HP ProBook 655 G3 11.39.2168.57, Q,53 SP80320 Windows 10: 8.65.205.1 Windows 7: 8.65.205.1 HP ProBook x360 11 G1 EE 8.65.211.51, A,14 SP80334 8.65.211.51 HP Spectre Pro 13 G1 8.65.170.1 A,37 SP80331 8.65.170.1 HP ZBook 15 G3 Mobile Workstation 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ZBook 15 G4 Mobile Workstation 11.44.2168.60, Q,53 SP80322 Windows 10: 9.0.139.1 Windows 7: 8.65.208.51 HP ZBook 15u G3 Mobile Workstation 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ZBook 15u G4 Mobile Workstation 11.39.2168.57, Q,53 SP80320 Windows 10: 9.0.136.1 Windows 7: 8.65.205.1 HP ZBook 17 G3 Mobile Workstation 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ZBook 17 G4 Mobile Workstation 11.44.2168.60, Q,53 SP80322 Windows 10: 9.0.139.1 Windows 7: 8.65.208.51 HP ZBook Studio G3 Mobile Workstation 10.0.931.90, Q,52 SP80323 Windows 10: 9.0.134.1 Windows 8.1: 9.0.134.1 Windows 7: 8.65.204.1 HP ZBook Studio G4 Mobile Workstation 11.44.2168.60, Q,53 SP80322 Windows 10: 9.0.139.1 Windows 7: 8.65.208.51 Commercial Desktops HP Elite Slice (Win 7) 8.65.166.1, A,1 SP80319 HP Elite Slice (Win10) 8.65.198.1, A,1 SP80318 HP EliteDesk 800 35W G3 Desktop Mini PC 8.65.186.51, A,1 SP80317 HP EliteDesk 800 65W G3 Desktop Mini PC 8.65.186.51, A,1 SP80317 HP EliteDesk 800 G3 Small Form Factor PC 8.65.186.51, A,1 SP80317 HP EliteDesk 800 G3 Tower PC 8.65.186.51, A,1 SP80317 HP EliteDesk 880 G3 Tower PC 8.65.186.51, A,1 SP80317 HP EliteOne 800 G3 23.8-inch Non-Touch All-in-One PC 8.65.186.1, B,1 SP80316 HP EliteOne 800 G3 23.8-inch Touch All-in-One PC 8.65.186.1, B,1 SP80316 HP ProDesk 400 G3 Desktop Mini PC 8.65.186.51, A,1 SP80317 HP ProDesk 400 G4 Microtower PC 8.65.186.51, A,1 SP80317 HP ProDesk 400 G4 Small Form Factor PC 8.65.186.51, A,1 SP80317 HP ProDesk 480 G4 Microtower PC 8.65.186.51, A,1 SP80317 HP ProDesk 600 G3 Desktop Mini PC 8.65.186.51, A,1 SP80317 HP ProDesk 600 G3 Microtower PC 8.65.186.51, A,1 SP80317 HP ProDesk 600 G3 Small Form Factor PC 8.65.186.51, A,1 SP80317 HP ProDesk 680 G3 Microtower PC 8.65.186.51, A,1 SP80317 Consumer Notebooks Product Name Fixed Version(s) SoftPaq # HP ENVY Notebook 15-as000-as099 8.65.169.1, A,46 SP80324 HP ENVY Notebook 15t-as00 8.65.169.1, A,46 SP80324 HP ENVY Notebook m1-u100-u199 9.0.134.1, A,47 SP80327 HP ENVY Notebook 17-u100-u199 9.0.134.1, A,47 SP80327 HP ENVY Notebook 17t-u000 9.0.134.1, A,47 SP80327 HP ENVY Notebook 15-as100-as199 9.0.134.1, A,47 SP80327 HP ENVY Notebook 15t-as100 9.0.134.1, A,47 SP80327 HP ENVY x360 m6-ar0xx 8.65.176.1, F,4 SP80336 HP ENVY x360 15-ar0xx 8.65.176.1, F,4 SP80336 HP ENVY x360 m6-aq0xx 8.65.165.11, A,2 SP80329 HP ENVY x360 15-aq0xx 8.65.165.11, A,2 SP80329 HP ENVY x360 m6-aq1xx 8.65.203.1, F,3 SP80328 HP ENVY x360 15-aq1xx 8.65.203.1, F,3 SP80328 HP Spectre 13-v000 ~ 13-v099 8.65.170.1, A,37 SP80331 HP Spectre 13-v100 ~ 13-v199 9.0.134.1, A,38 SP80333 HP ENVY x360 13-y0xx 9.0.140.1, C,6 SP80332 System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. "HP is broadly distributing this Security Bulletin to alert users of affected HP products about the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement." ... Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send an e-mail to hp-security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send e-mail to: hp-security-alert@hp.com. Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email, visit https://h41369.www4.hp.com/alerts-signup.php?lang=en&cc=US&jumpid=hpsc_profile. Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. PI HP Printing and Imaging HF HP Hardware and Firmware ST HP Storage Software GN HP General Software Support: For further information, contact normal HP Services support channel. Report: To report a potential security vulnerability with any HP supported product, send Email to: hp-security-alert@hp.com. It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. To get the security-alert PGP key, please send an e-mail message as follows: To: hp-security-alert@hp.com Subject: get key System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. "HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement." REVISION HISTORY : 11 May 2017: Initial release. 15, May 2017: Updated tables with more softpaqs. Fixed spelling errors. Corrected 2 product names. 16 May 2017: Updated SP80325 to SP80336 - fixing broken link due to superceded executable. Added column of fixed vendor version numbers by OS to commercial notebook table. Copyright 2017 HP Development Company, L.P. HP Inc. shall not be liable for technical or editorial errors or omissions contained herein.The information provided is provided "as is" without warranty of any kind.To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restorationThe information in this document is subject to change without notice.HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries.Other product and company names mentioned herein may be trademarks of their respective owners. - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWSTwgYx+lLeg9Ub1AQgruBAAiX1HGjTTGY3nXaV16m6PJvGzrBUdQEmh /DAuyr1ODBuwIPz0StWn3NdLHftkr8Cyfg1sLfOO8pUIVrvXqCp+6l6HoDCeiims 76WTgUDSPuw2DycBk6CwlvLJRPr/IPunCZ/3F4cKwRXkGc1i/BGgzmgck4BU1Jza Usjs4D74mji0rjcQtS5EiTP/GeFC+nnBlQHAE++qNnIQpp9W40LlqIuNYcM+31I7 gtx8kXlfGzK6snZcQlib7eJR2l7oU0KOQ9NXw1Vd0ecAL+sQ20BB+fgjxRwhBAlA JCZHuhyBCoXWGJAocFUn/4Lo6JCAS7DLRgVb2N+OgVmqxFwBqUwy1u7iQNSPYYwm K4DJWW6QYfHJDHe3CPmMjLtTFNLtJqv3ybg7ik54kBwWOIkmrMGlel8bHysl3+Gv MNHWADi3WV+rFtxP13TtbKuq4VepQIOomPeTbDTjQaZbnIZyC8OrN5umJvSW7oFn WoSIV3zJTbhBBPxPCZCTY9gz/FynN7i9uDspWkfP7hJSaQm/wH0LhnJBE6sIGkH6 Szvth2ChhUCcXX/S+VIPyzblpvIZ1AMP99gqOGzgGnhSwP4LmeCHGcArkHRQQ7t5 BWC1Ln7+xuhSKEXK7mczJ1kBPWL68aOHIctSGfywmNu9gLl5ZNmo+Z7/vf0joJSq 5/i8TpvRz30= =buoj -----END PGP SIGNATURE-----