Three different vulnerabilities were discovered (and immediately published in a PoC) in pre-installed software of Dell, Lenovo and Toshiba computers (computers and tablets) affecting millions of users.
A PoC (proof-of-concept) posted online demonstrates that the vulnerabilities allow an attacker to execute system-level malware, regardless of what type of user is logged in.
According to the researcher who wrote the PoC, a user can be tricked into opening a specially crafted website to download a file, which can also come as an email attachment. These files allow an attacker to exploit the flaw.
Security researcher slipstream/RoL published his findings without informing any of the three companies Dell, Lenovo, and Toshiba.
All three vulnerabilities discovered by the researcher (found in the Carnegie Mellon University or CERT database) are found in pre-installed software often known as “bloatware.”
Lenovo Solution Center, an application designed to give the user a quick overview of the system's health, security, and network status, comes pre-installed on a number of products. These include ThinkPads, ThinkCenter and ThinkStation, IdeaCenter, and some IdeaPads, running Windows 7 or later.
On Toshiba systems , a security vulnerability was also discovered in the pre-installed Toshiba Service Station, which serves software updates among other things.
According to researcher slipstream/RoL, the application allows a logged-in user to read parts of the registry as the system user, which has higher privileges than a standard user account. The researcher said an attacker cannot read the security account manager (SAM) or bootkeys, but it is possible to “bypass special privileges from the registry.”
In Dell systems , two vulnerabilities were found by the same security researcher.
The pre-installed Dell System Detect application, which checks a user's system for potential issues before contacting support, can be used to bypass a Windows security feature that escalates a user's privileges.
The security flaws come just a week after allegations were made that Dell was using a pre-installed security certificate that allowed an attacker to intercept traffic and conduct man-in-the-middle attacks.
Here we should mention that millions of systems are affected by the above security vulnerabilities, due to the increased sales of these companies.
As for bloatware, also known as crapware, it continues to be a major security issue for any system that uses it. Lenovo, which was previously caught using the Superfish adware, has promised to stop bundling pre-installed bloatware on its computers.
See the PoC
