Researchers find a trio of serious flaws in Lenovo PCs

Shawn Knight

Posts: 15,292   +192
Staff member

massive security risk lenovo computers patch vulnerability flaw superfish lenovo computer ioactive

Less than three months after Lenovo’s embarrassing Superfish fiasco, the Chinese PC maker is under the microscope once again. Security research firm IOActive recently disclosed that it found a trio of vulnerabilities related to the company’s System Update feature.

One of the vulnerabilities allows both local and remote attackers to replace trusted Lenovo applications with malicious apps of their own that can then be run as a privileged user. Another flaw takes advantage of a weakness in Lenovo’s security token system while the third vulnerability lets unprivileged local users run commands as an administrator.

Fortunately for Lenovo, IOActive did the right thing and reported the vulnerabilities before going public with their findings. This gave the PC maker plenty of time to get the issues worked out via a patch issued last month. The flaws were originally discovered by Michael Milvich and Sofiane Talmat.

The flaw is said to affect all ThinkPad, ThinkCenter and ThinkStation products as well as B, E, K and V-series systems.

You can determine the currently installed version by opening Lenovo System Update, clicking on the green question mark in the top right corner and then selecting “about.” If you are running version 5.6.0.27 or earlier, you’ll want to go ahead and update as soon as possible. Another option would be to simply wipe your device and install your own copy of Windows.

Permalink to story.

 
I usually wipe the hard drive on new computers and install my own copy of Windows. Just more reason to continue to do so.
 
Software flaws? Not much of a problem. Write about hardware/electronics flaws that shenzhen topstar/lenowo makes. Or poor quality materials used by them.
 
Backdoors in hardware from a Chinese vendor? Nooooooo....I'm shellshocked.
 
You were just advertising Lenovo, 3 days ago too Techspot! Shame on you.
 
Backdoors in hardware from a Chinese vendor? Nooooooo....I'm shellshocked.

Oh give me a break ....... your very own Windows system has a bevy of back doors, all courtesy of our USA based Microsoft.
Prove it!

Stop spreading FUD!

shill or trolling?

http://en.wikipedia.org/wiki/Windows_Error_Reporting#Privacy_concerns_and_use_by_the_NSA
http://www.technobuffalo.com/2013/08/22/nsa-windows-8-exploit/

Search the rest yourself its easy, it isn't even debatable anymore weather windows has been/is backdoored, it's common knowledge. + they still push for more.
 
Back