-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2017.1326
       HPSBGN03558 rev.7 - Conexant HD Audio Driver Local Debug Log
                                24 May 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Conexant HD Audio Driver
Publisher:         Hewlett-Packard
Operating System:  Windows
Impact/Access:     Access Privileged Data -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         PSR-2017-0067  

Original Bulletin: 
   https://support.hp.com/us-en/document/c05519670

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Note: the current version of the following document is available here:
https://support.hp.com/us-en/document/c05519670

SUPPORT COMMUNICATION- SECURITY BULLETIN

Document ID: c05519670
Version: 1

HPSBGN03558 rev.7 - Conexant HD Audio Driver Local Debug Log
Notice:: The information in this security bulletin should be acted upon as soon
as possible.

Release date : 12-May-2017
Last updated : 16-May-2017

Potential Security Impact:
Potential, local loss of confidentiality

Source:HP, HP Product Security Response Team (PSRT)

VULNERABILITY SUMMARY

A potential security vulnerability caused by a local debugging capability that
was not disabled prior to product launch has been identified with certain
versions of Conexant HD Audio Drivers on HP products. HP has no access to
customer data as a result of this issue.

References:

* CVE TBD=20
* PSR-2017-0067

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

See the RESOLUTION section for impacted products.

BACKGROUND

For a PGP signed version of this security bulletin please write to:
hp-security-alert@hp.com

CVSS 3.0 Base Metrics
===========================================================================

Reference 	Base Vector                                  	Base Score
CVE TBD        CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 	6.5
===========================================================================

Information on CVSS is documented in HP Customer Notice: HPSN2008002.

RESOLUTION

HP has provided software updates for Conexant HD Audio Driver. Impacted HP
products are shown in the table below. We will update the table as SoftPaqs
become available.

Commercial Notebooks

 Product Name                           SoftPaq Bundle Version(s)      SoftPaq #       Fixed Vendor Version(s)
HP Elite x2 1012 G1                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 725 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP EliteBook 725 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP EliteBook 745 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP EliteBook 745 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP EliteBook 755 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP EliteBook 755 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP EliteBook 820 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 820 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP EliteBook 828 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 828 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP EliteBook 840 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 840 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP EliteBook 848 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 848 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP EliteBook 850 G3                    10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook 850 G4                    11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP EliteBook Folio 1030 G1             10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook Folio 1040 G3             10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook Folio G1                  10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP EliteBook x360 1030 G2              11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP mt20 Mobile Thin Client             11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP mt42 Mobile Thin Client             10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP mt43 Mobile Thin Client             11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP Pro X2 612 G2                       11.39.2168.58, Q,53            SP80321        Windows 10: 9.0.137.1   Windows 7: 8.65.207.1
HP ProBook 11 G2                       9.0.134.1, A,10                SP80330        9.0.134.1
HP ProBook 430 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 430 G4                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 440 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 440 G4                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 446 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 450 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 450 G4                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 455 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP ProBook 455 G4                      11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP ProBook 470 G3                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 470 G4                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 640 G2                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 640 G3                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 645 G2                      10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP ProBook 645 G3                      11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP ProBook 650 G2                      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ProBook 650 G3                      11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ProBook 655 G2                      10.0.931.90, Q,52              SP80323        Windows 10: 8.65.204.1   Windows 8.1: 8.65.204.1   Windows 7: 8.65.204.1
HP ProBook 655 G3                      11.39.2168.57, Q,53            SP80320        Windows 10: 8.65.205.1   Windows 7: 8.65.205.1
HP ProBook x360 11 G1 EE               8.65.211.51, A,14              SP80334        8.65.211.51
HP Spectre Pro 13 G1                   8.65.170.1 A,37                SP80331        8.65.170.1
HP ZBook 15 G3 Mobile Workstation      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ZBook 15 G4 Mobile Workstation      11.44.2168.60, Q,53            SP80322        Windows 10: 9.0.139.1   Windows 7: 8.65.208.51
HP ZBook 15u G3 Mobile Workstation     10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ZBook 15u G4 Mobile Workstation     11.39.2168.57, Q,53            SP80320        Windows 10: 9.0.136.1   Windows 7: 8.65.205.1
HP ZBook 17 G3 Mobile Workstation      10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ZBook 17 G4 Mobile Workstation      11.44.2168.60, Q,53            SP80322        Windows 10: 9.0.139.1   Windows 7: 8.65.208.51
HP ZBook Studio G3 Mobile Workstation  10.0.931.90, Q,52              SP80323        Windows 10: 9.0.134.1   Windows 8.1: 9.0.134.1   Windows 7: 8.65.204.1
HP ZBook Studio G4 Mobile Workstation  11.44.2168.60, Q,53            SP80322        Windows 10: 9.0.139.1   Windows 7: 8.65.208.51


Commercial Desktops
HP Elite Slice (Win 7)                                8.65.166.1, A,1       SP80319
HP Elite Slice (Win10)                                8.65.198.1, A,1       SP80318
HP EliteDesk 800 35W G3 Desktop Mini PC               8.65.186.51, A,1      SP80317
HP EliteDesk 800 65W G3 Desktop Mini PC               8.65.186.51, A,1      SP80317
HP EliteDesk 800 G3 Small Form Factor PC              8.65.186.51, A,1      SP80317
HP EliteDesk 800 G3 Tower PC                          8.65.186.51, A,1      SP80317
HP EliteDesk 880 G3 Tower PC                          8.65.186.51, A,1      SP80317
HP EliteOne 800 G3 23.8-inch Non-Touch All-in-One PC  8.65.186.1, B,1       SP80316
HP EliteOne 800 G3 23.8-inch Touch All-in-One PC      8.65.186.1, B,1       SP80316
HP ProDesk 400 G3 Desktop Mini PC                     8.65.186.51, A,1      SP80317
HP ProDesk 400 G4 Microtower PC                       8.65.186.51, A,1      SP80317
HP ProDesk 400 G4 Small Form Factor PC                8.65.186.51, A,1      SP80317
HP ProDesk 480 G4 Microtower PC                       8.65.186.51, A,1      SP80317
HP ProDesk 600 G3 Desktop Mini PC                     8.65.186.51, A,1      SP80317
HP ProDesk 600 G3 Microtower PC                       8.65.186.51, A,1      SP80317
HP ProDesk 600 G3 Small Form Factor PC                8.65.186.51, A,1      SP80317
HP ProDesk 680 G3 Microtower PC                       8.65.186.51, A,1      SP80317

Consumer Notebooks

Product Name                    Fixed Version(s) SoftPaq #
HP ENVY Notebook 15-as000-as099 8.65.169.1, A,46 SP80324
HP ENVY Notebook 15t-as00       8.65.169.1, A,46 SP80324
HP ENVY Notebook m1-u100-u199   9.0.134.1, A,47  SP80327
HP ENVY Notebook 17-u100-u199   9.0.134.1, A,47  SP80327
HP ENVY Notebook 17t-u000       9.0.134.1, A,47  SP80327
HP ENVY Notebook 15-as100-as199 9.0.134.1, A,47  SP80327
HP ENVY Notebook 15t-as100      9.0.134.1, A,47  SP80327
HP ENVY x360 m6-ar0xx           8.65.176.1, F,4  SP80336
HP ENVY x360 15-ar0xx           8.65.176.1, F,4  SP80336
HP ENVY x360 m6-aq0xx           8.65.165.11, A,2 SP80329
HP ENVY x360 15-aq0xx           8.65.165.11, A,2 SP80329
HP ENVY x360 m6-aq1xx           8.65.203.1, F,3  SP80328
HP ENVY x360 15-aq1xx           8.65.203.1, F,3  SP80328
HP Spectre 13-v000 ~ 13-v099    8.65.170.1, A,37 SP80331
HP Spectre 13-v100 ~ 13-v199    9.0.134.1, A,38  SP80333
HP ENVY x360 13-y0xx            9.0.140.1, C,6   SP80332

System management and security procedures must be reviewed frequently to
maintain system integrity. HP is continually reviewing and enhancing the
security features of software products to provide customers with current secure
solutions.

"HP is broadly distributing this Security Bulletin to alert users of affected
HP products about the important security information contained in this
Bulletin. HP recommends that all users determine the applicability of this
information to their individual situations and take appropriate action. HP does
not warrant that this information is necessarily accurate or complete for all
user situations and, consequently, HP will not be responsible for any damages
resulting from user's use or disregard of the information provided in this
Bulletin. To the extent permitted by law, HP disclaims all warranties, either
express or implied, including the warranties of merchantability and fitness for
a particular purpose, title and non-infringement."
...
Third Party Security Patches: Third party security patches that are to be
installed on systems running HP software products should be applied in
accordance with the customer's patch management policy.

Support: For issues about implementing the recommendations of this Security
Bulletin, contact normal HP Services support channel. For other issues about
the content of this Security Bulletin, send an e-mail to
hp-security-alert@hp.com.

Report: To report a potential security vulnerability with any HP supported
product, send e-mail to: hp-security-alert@hp.com.

Subscribe: To initiate a subscription to receive future HP Security Bulletin
alerts via Email, visit 
https://h41369.www4.hp.com/alerts-signup.php?lang=en&cc=US&jumpid=hpsc_profile.

Software Product Category: The Software Product Category is represented in the
title by the two characters following HPSB.

PI HP Printing and Imaging
HF HP Hardware and Firmware
ST HP Storage Software
GN HP General Software

Support: For further information, contact normal HP Services support channel.

Report: To report a potential security vulnerability with any HP supported
product, send Email to: hp-security-alert@hp.com.
It is strongly recommended that security related information being communicated
to HP be encrypted using PGP, especially exploit information.

To get the security-alert PGP key, please send an e-mail message as follows:
To: hp-security-alert@hp.com
Subject: get key

System management and security procedures must be reviewed frequently to
maintain system integrity. HP is continually reviewing and enhancing the
security features of software products to provide customers with current secure
solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the
attention of users of the affected HP products the important security
information contained in this Bulletin.HP recommends that all users determine
the applicability of this information to their individual situations and take
appropriate action.HP does not warrant that this information is necessarily
accurate or complete for all user situations and, consequently, HP will not be
responsible for any damages resulting from user's use or disregard of the
information provided in this Bulletin.To the extent permitted by law, HP
disclaims all warranties, either express or implied, including the warranties
of merchantability and fitness for a particular purpose, title and
non-infringement."

REVISION HISTORY : 11 May 2017: Initial release. 15, May 2017: Updated tables
with more softpaqs. Fixed spelling errors. Corrected 2 product names. 16 May
2017: Updated SP80325 to SP80336 - fixing broken link due to superceded
executable. Added column of fixed vendor version numbers by OS to commercial
notebook table.

Copyright 2017 HP Development Company, L.P.

HP Inc. shall not be liable for technical or editorial errors or omissions
contained herein.The information provided is provided "as is" without warranty
of any kind.To the extent permitted by law, neither HP or its affiliates,
subcontractors or suppliers will be liable for incidental, special or
consequential damages including downtime cost; lost profits; damages relating
to the procurement of substitute products or services; or damages for loss of
data, or software restorationThe information in this document is subject to
change without notice.HP Inc. and the names of HP products referenced herein
are trademarks of HP Inc. in the United States and other countries.Other
product and company names mentioned herein may be trademarks of their
respective owners.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWSTwgYx+lLeg9Ub1AQgruBAAiX1HGjTTGY3nXaV16m6PJvGzrBUdQEmh
/DAuyr1ODBuwIPz0StWn3NdLHftkr8Cyfg1sLfOO8pUIVrvXqCp+6l6HoDCeiims
76WTgUDSPuw2DycBk6CwlvLJRPr/IPunCZ/3F4cKwRXkGc1i/BGgzmgck4BU1Jza
Usjs4D74mji0rjcQtS5EiTP/GeFC+nnBlQHAE++qNnIQpp9W40LlqIuNYcM+31I7
gtx8kXlfGzK6snZcQlib7eJR2l7oU0KOQ9NXw1Vd0ecAL+sQ20BB+fgjxRwhBAlA
JCZHuhyBCoXWGJAocFUn/4Lo6JCAS7DLRgVb2N+OgVmqxFwBqUwy1u7iQNSPYYwm
K4DJWW6QYfHJDHe3CPmMjLtTFNLtJqv3ybg7ik54kBwWOIkmrMGlel8bHysl3+Gv
MNHWADi3WV+rFtxP13TtbKuq4VepQIOomPeTbDTjQaZbnIZyC8OrN5umJvSW7oFn
WoSIV3zJTbhBBPxPCZCTY9gz/FynN7i9uDspWkfP7hJSaQm/wH0LhnJBE6sIGkH6
Szvth2ChhUCcXX/S+VIPyzblpvIZ1AMP99gqOGzgGnhSwP4LmeCHGcArkHRQQ7t5
BWC1Ln7+xuhSKEXK7mczJ1kBPWL68aOHIctSGfywmNu9gLl5ZNmo+Z7/vf0joJSq
5/i8TpvRz30=
=buoj
-----END PGP SIGNATURE-----