Lenovo PCs Have 'Massive Security Risk' Say Researchers; Fix Issued

Advertisement
By Ketan Pratap | Updated: 7 May 2015 15:19 IST
Lenovo's image has taken another hit with a report of another software-related glitch on its computers that could potentially allow attackers to bypass signature validation checks and replace trusted Lenovo applications with malware.

Security researchers Michael Milvich and Sofiane Talmat of IOActive discovered a 'massive security risk' in the Lenovo System Update software in February, and reported the issue to the world's biggest PC maker. The researchers have now made the vulnerabilities public after Lenovo has issued a patch for the application.

The Chinese company has posted a patch for consumers on its support page titled "Lenovo System Update Privilege Escalation." Affected machines in the Lenovo lineup are the Lenovo ThinkPad, ThinkCentre, ThinkStation, and other Lenovo laptop (V, B, K, and E) series. Users of these machines can either run Lenovo System Update and install the new version when prompted by the app, or download and install the latest version manually.

Milvich and Talmat of IOActive have detailed three vulnerabilities in the Lenovo System Update software in a security advisory. According to the IOActive security advisory, the CVE-2015-2219 vulnerability allows local least-privileged users to run commands as the system user. The CVE-2015-2233 vulnerability, on the other hand, allows a hacker to replace the trusted company software with any malicious software.

Advertisement

"Remote attackers who can perform a man in the middle attack (the classic coffee shop attack) can exploit this to swap Lenovo's executables with a malicious executable. The System Update uses TLS/SSL to secure its communications with the update server, which should protect against "coffee shop" style attacks," notes the IOActive security advisory. Lastly, CVE-2015-2234 vulnerability allows local unprivileged users to run commands as an administrative user.

All the vulnerabilities reported by security researchers have been fixed in the new version of the Lenovo System Update software released by the Chinese firm, confirms IOActive security advisory. Lenovo has also thankedMilvich and Talmat of IOActive for reporting issues to the company in a responsible manner.

To recall, Lenovo faced much flak back in February when it was found to be pre-installing Superfish software, classified as adware by researchers, on its computers. After defending the software as a shopping tool to aid users, the world's largest PC maker promised to stop pre-installing such software.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X200T With Zeiss Cameras to Launch in India on This Date
  2. Redmi Note 15 Pro Series Might Launch in India With These Storage Options
  3. Motorola Edge 70 Fusion Leak Reveals Full Specifications Ahead of Launch
  4. Here's When the Realme P4 Power 5G Will Launch in India
  5. Google Pixel 10a Leak Suggests No Price Hike Over Pixel 9a
  6. Sony to Cede Control of Bravia TVs to China's TCL Electronics
  7. OneUI 8.5 Beta 4 Could Roll Out Soon With Upgraded Bixby, New Features
  8. iQOO 15R Will Be Launched in India Soon, Company Confirms
  9. Samsung Takes the Apple Route With Perplexity-Powered Bixby Features
  10. Nearly All Indian Creators Believe AI Is Powering Their Growth: Adobe
  1. Scientists Find Clue to High-Temperature Superconductivity in Quantum Materials
  2. New Dark Matter Simulation Could Change How Galaxies Are Thought to Evolve
  3. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  4. Sony to Cede Control of Bravia TVs to China’s TCL Electronics
  5. Adobe Premiere Integrated With AI-Powered Firefly Platform; New After Effects Features Rolling Out
  6. Samsung Upgrades Bixby With Perplexity-Powered AI Features, Takes Page Out of Apple’s Playbook
  7. Google Reportedly Working On New Live Features and Agentic Mode for Gemini Assistant
  8. Redmi Note 15 Pro+, Redmi Note 15 Pro RAM and Storage Options, Key Specifications Leaked Ahead of India Launch
  9. Eddington Arrives on OTT: What You Need to Know About Joaquin Phoenix and Pedro Pascal Starrer Thriller
  10. Red Magic 11 Air Launched With Snapdragon 8 Elite, RedCore R4 Gaming Chip and 7,000mAh Battery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.