HomeSecuritySecurity flaws in Lenovo computers

Security flaws in Lenovo computers

Security flaws in Lenovo computers

Lenovo has issued a patch for a flaw in its computers that researchers say could allow hackers to replace trusted apps with malicious versions of themselves. 

Security researchers at IOActive have announced three separate vulnerabilities that hackers could exploit that could bypass checks to ensure the integrity of apps, allowing them to run malware on an affected Lenovo machine.

lenovo-superfish

“An attacker can create a fake [certificate authority] and use it to create a code-signing certificate, which can then be used to sign executables,” the advisory states. “Because System Update failed to properly validate the certificate authority, System Update will accept executables signed by the fake certificate and run them as a privileged user.”

The “high”-rated flaw affects all ThinkPad, ThinkCenter, and ThinkStation products, along with V, B, K, and E-series machines.

The latest security flaw came shortly after the company admitted to installing internet traffic-intercepting software on some notebooks. The company initially denied the incident but later issued a fix to remove the software.

Other flaws that have been fixed include a bug that allowed a lower-level user to bypass user restrictions and run malware as the “system” user, and a bug in how Lenovo’s system update service works to potentially allow a similar escalation of user privileges.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS