In case you are using a Lenovo with a built-in fingerprint sensor, you might want to install the company's latest security patch update.
According to a security advisory published last week, the Lenovo Fingerprint Manager Pro software on many ThinkPad, ThinkCentre, and ThinStation systems contains a critical local privilege escalation vulnerability (CVE-2017-3762).
The software stores sensitive information, such as user biometric data and Windows login credentials. However, the data is encrypted with a weak algorithm and also contains a password that all users can access. An attacker can see the login credentials and fingerprint data, but physical access to the system is required.
The vulnerability currently affects Lenovo ThinkPad systems running Windows 7, 8, 8.1. The list includes:
ThinkPad L560
ThinkPad P40 Yoga, P50s
ThinkPad T440, T440p, T440s, T450, T450s, T460, T540p, T550, T560
ThinkPad W540, W541, W550
ThinkPad X1 Carbon (Model 20A7, 20A8), X1 Carbon (Model 20BS, 20BT)
ThinkPad X240, X240, X250, X260
ThinkPad Yoga 14 (20FY), Yoga 460
ThinkCentre M73, M73z, M78, M79, M83, M93, M93p, M93z
ThinkStation E32, P300, P500, P700, P900
Lenovo has released an updated patch version to fix the issue. Fingerprint Manager Pro needs to be updated to version 8.01.87 and above.
Users running Windows 10 can be confident that the vulnerability does not pose threats to their machines, as the company informed. Windows 10 users do not need to install the updated version of the fingerprint manager. The reason these devices are not affected is that they use Windows Hello, which is Microsoft’s fingerprint recognition software.
