A 36-page report published by Duo Security reveals the sad state of bloatware that OEMs use on laptops and beyond. Bloatware is the term used to describe annoying programs that usually come as driver updaters. More often than not, it's also referred to as crapware, and it comes pre-installed on your new laptop by the company itself.
The Duo Security research team conducted checks on the built-in software that comes as a driver updater on laptops from Acer, Asus, Dell, Hewlett-Packard (HP), and Lenovo.
The results of their analysis were very worrying.
[su_note note_color=”#6f6f6f” text_color=”#ffffff” radius=”0″]For those who didn’t understand, we’re talking about vulnerable bloatware that’s already on the system before you even use it, straight from the company. Of course, what you’ll read below doesn’t explain the reasons for using such software by big manufacturing names, but it’s not hard to guess….[/su_note]
What Duo Security's research team discovered is that many laptop and notebook manufacturers (OEMs or Original Equipment Manufacturers) use applications with many security issues that sometimes give the attacker full rights to the devices.
“We broke them all, and some were worse than others. Every company had at least one vulnerability that could allow man-in-the-middle (MITM) attacks and arbitrary code execution on the system.”
Duo's team reports that the driver update software that comes with every laptop contains at least one security flaw that allows an attacker to execute code on the user's laptop and take over the device.
Even worse, Duo says that very few companies know how to properly implement TLS encryption, which explains why we've seen incidents like Superfish and eDellRoot from time to time.
Furthermore, Duo reveals that very few companies know how to validate and verify the integrity of updates downloaded by the driver updaters they use, leaving users exposed to downloading fake (malicious) drivers.
If you take a look at the table below, you'll see that the Lenovo Solution Center driver update tool has positive results in Duo's tests.
The tool may be safe now, but it wasn't before.
Security researchers have been bombarding Lenovo with complaints and bug reports over the past few months, ultimately helping the company implement better security in its app, which just received an update earlier this month to fix some of the reported issues.
Out-of-Box Exploitation: A Security Analysis of OEM Updaters
