Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Researchers find a “massive security risk” on Lenovo devices, patch released – onmsft.com

Researchers find a “massive security risk” on Lenovo devices, patch released – onmsft.com

Sean Michael Sean Michael
May 6, 2015
2 min read

Lenovo

As the saying goes, fool me once shame on you, fool me twice shame on me. Lenovo is putting that idiom to the test. According to a report by the BBC a “massive security risk” of Lenovo devices has been found by researchers. This news comes only months after the ‘superfish’ news in which preinstalled adware created security issues.

There are a number of security flaws that were uncovered by IOActive. First, according to the researchers attackers could “bypass signature validation checks and replace trusted Lenovo applications with malicious applications.” This would allow people to hack a public Wi-Fi network and “exploit this to swap Lenovo’s executables with a malicious executable.” These are often referred to as “coffee shop attacks.”

Second, people could utilize the security flaw to “gain elevated permissions.” In the report they state that

“A local attacker could exploit this to perform a local privilege escalation by waiting for the System Update to verify the signature of the executable, and then swapping out the executable with a malicious version before the System Update is able to run the executable. When the System Update gets around to running the executable, it will run the malicious version, thinking it was the executable that it had already verified.”

These security flaws stem from the fact that “The Lenovo System Update allows least privileged users to perform system updates.” This means that attackers can act as if they were a privileged user and perform system updates.

There is a bit of good news to all of this. There has been a patch released to fix these reported issues. IOActive discovered reported the issues to Lenovo in February and a patch to fix them was released on April 3, 2015.

This is another blow to the integrity and security of Lenovo. It will be interesting to see how repeated security risks affect their bottom line.

Share This Post:

Share this article:
Tags:
Lenovo Security
Previous Article Dropbox will soon allow iOS users to create Office documents from within the app Next Article Here are the legacy technologies that were removed in Microsoft Edge | On MSFT

Related Articles

Intel Nova Lake May Beat Zen 6 in IPC, But AMD Could Take Clock Speed Crown

April 6, 2026
Intel Panther Lake laptops see major price hikes due to component shortages, while Apple MacBook M5 models continue with unchanged pricing globally.

Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable

April 5, 2026
State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

April 5, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Intel Nova Lake May Beat Zen 6 in IPC, But AMD Could Take Clock Speed Crown
  • Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable
  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Intel Nova Lake May Beat Zen 6 in IPC, But AMD Could Take Clock Speed Crown
  • Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable
  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy