Hundreds of laptop models from HP shipped with keyloggers, again
Here we go again.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
If HP needs ideas on a New Year's resolution, how about no more keyloggers in 2018? We bring this up because as 2017 comes to a close, HP is once again issuing a patch to address keylogging code found in preinstalled software drivers on some of its laptops.
The last time this happened, it was related to a Conexant audio driver on dozens of laptop models. This time it has to do with the keyboard and touchpad, and it affects 460 laptop models dating back to 2012.
Security researcher Michael Myng discovered the hidden keylogger when someone asked him if he could figure out a way to control HP's keyboard backlight.
"I asked for the keyboard driver SynTP.sys, opened it in IDA and after some browsing noticed a few interesting strings," Myng explains.
Those "interesting strings" turned out to be a dormant keylogger that is disabled by default. However, an attacker with access to an affected model could enable it to record a user's keystrokes.
"A potential security vulnerability has been identified with certain versions of Synaptics touchpad drivers that impacts all Synaptics OEM partners. A party would need administrative privileges in order to take advantage of the vulnerability. Neither Synaptics nor HP has access to customer data as a result of this issue," HP stated in a security bulletin.
Some of the affected models include HP's EliteBook, Pavilion, ProBook, ZBook, Envy, and Spectre. Many older Compaq models are on the list as well.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
There are separate updates available for the many different models. You will need your laptop's model number to grab the right one. Once you have that, scroll down the security bulletin until you find your model and download the accompanying update.
Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).


