Almost all modern computers have Absolute's Computrace built into the BIOS. Computrace is essentially anti-theft software that allows companies to monitor their computers from a single cloud-based console.
The software can be used to facilitate the tracking of a stolen or lost device, after the corresponding service has been activated by Absolute.
However, Kaspersky Lab researchers have revealed that this software often runs without the user's knowledge, is persistently activated at system startup, and can be exploited to carry out various attacks and gain full control of an infected computer.
Kaspersky researchers Vitaly Kamluk and Sergey Belov , along with Core Security's Annibal Sacco, recently demonstrated the vulnerability in a presentation at the Black Hat 2014 conference.
This particular issue was first presented by researcher Kamluk at Kaspersky Security's Analyst Summit in February:
"The software is extremely flexible. It's a small piece of code that's part of the BIOS. And as a part of the BIOS, it's not very easy to get updates very often. So they made it very extensible. It can do almost anything. It can run any type of code," the researcher had said.
“You can do whatever you want with the system. Considering that the software runs with local system privileges, you have full access to the machine. You can monitor it, you can see through the camera, you can copy all the files, you can start new processes. You can really do everything.”.
Computrace continues to be exploitable six months after the issue was identified, and once activated, it is very persistent and difficult to disable, Kaspersky. It also does not enforce encryption when communicating with servers and does not verify the identity of the servers from which it receives commands, which could expose users to attacks.

