In our previous post, we reported on the risks posed to user privacy by Lenovo's LSE program. Today, we received the company's official announcement via its representative on this specific issue.
So let us inform you of Lenovo's official statement:
In April-May, Lenovo released new BIOS firmware for some of its consumer PCs that did not include a security vulnerability discovered and reported by independent security researcher Roel Schouwenberg.
In collaboration with Mr. Schouwenberg and in line with industry best practices for privacy protection, on July 31, 2015, we issued Lenovo Product Security Advisories, which highlight the new BIOS firmware – specifically for consumer Notebook and Desktop.
Lenovo strongly recommends that users keep their systems up to date with the latest BIOS firmware.
Starting in June, the new BIOS firmware has been installed on all new Lenovo consumer notebooks and desktop systems.
The vulnerability was linked to the way Lenovo uses the Microsoft Windows engine in a feature found in the BIOS firmware, called the Lenovo Service Engine (LSE), that was installed on some Lenovo consumer PCs. Think-brand PCs were not affected.
Together with this security researcher, Lenovo and Microsoft discovered potential ways in which this program could be exploited by an attacker, including a buffer overflow attack and an attempt to connect to a Lenovo test server.
As a result of these findings, Microsoft recently released updated security guidelines (see page 10 in the attached file) on how to best implement this Windows BIOS feature.
The use of Lenovo LSE was not compliant with these new guidelines. As a result, LSE is no longer installed on Lenovo systems. Customers are strongly advised to update their systems with the new BIOS firmware that disables or removes this feature.
LSE was shipped on certain Lenovo notebook systems running Windows 7, 8, and 8.1 and desktop systems running Windows 8 and 8.1. The software is not preinstalled on any Think-branded PCs.
