• the feed
    • Tech
    • Auto
    • Guides
    • Opinions
  • Reviews
    • READERS’ CHOICE
    • ALL REVIEWS
    • ━
    • SMARTPHONES
    • CARS
    • HEADPHONES
    • ACCESSORIES
    • LAPTOPS
    • TABLETS
    • WEARABLES
    • SPEAKERS
    • APPS
  • screen time
    • TV & MOVIE REVIEWS
    • SPOTLIGHT
  • GAMING
    • GAMING NEWS
    • GAME REVIEWS
  • quick bytes
Reading: Round 2: Lenovo is back in the news for a new security risk in their computers
Font ResizerAa
Font ResizerAa
  • menu
  • SEARCH
  • the feed
    • TECH
    • AUTOMOTIVE
    • GUIDES
    • OPINIONS
  • REVIEWS
    • READERS’ CHOICE
    • ALL REVIEWS
    • ━
    • SMARTPHONES
    • CARS
    • HEADPHONES
    • ACCESSORIES
    • LAPTOPS
    • TABLETS
    • WEARABLES
    • SPEAKERS
    • APPS
  • screen time
    • TV & MOVIE REVIEWS
    • SPOTLIGHT
  • GAMING
    • GAMING NEWS
    • GAME REVIEWS
  • quick bytes
Follow US

Round 2: Lenovo is back in the news for a new security risk in their computers

GEEK DESK
GEEK DESK
May 6, 2015

Few months after Lenovo’s SuperFish fiasco ended, the company is now back in the spotlight for a new security risk.

Security firm IOActive reported that it has discovered major vulnerabilities in Lenovo’s update system. The report claims that the vulnerabilities can give hackers access to bypass the company’s validation checks, and allow them to replace legitimate software with malicious software running in disguise, unspotted.

Should a Lenovo owner update their machine in a coffee shop, another individual could conceivably use the security hole to swap Lenovo’s programs with their own — what the researchers call the “classic coffee shop attack.” The security hole, along with others described by IOActive, are present in Lenovo System Update 5.6.0.27 and earlier versions, the Verge wrote.

We’ve reached out for comments and were able to get the following statement by a Lenovo Spokesperson:

Lenovo’s development and security teams worked directly with IOActive regarding their System Update vulnerability findings, and we value their expertise in identifying and responsibly reporting them. Lenovo released an updated version of System Update on April 1st which resolves these vulnerabilities and subsequently published a security advisory in coordination with IOActive at: https://support.lenovo.com/us/en/product_security/lsu_privilege.  Existing installations of System Update will prompt the user to automatically install the updated version when the application is run. Alternatively, users may manually update System Update as described in the security advisory.  Lenovo recommends that all users update System Update to eliminate the vulnerabilities reported by IOActive.

What do you think?
Happy0
Sad0
Love0
Surprise0
Cry0
Angry0
Dead0
I tried HONOR’s Robot Phone, and that moving camera is seriously wild
RØDECaster Video just got a huge 4K upgrade for free
REDMI Note 17 Series lands in UAE starting at AED 1,059
Spotify just handed your playlists to Meta’s Muse AI, and it’s oddly clever
Meta’s tiny Muse Charm wants to put AI in your pocket
Meta Glasses officially land in the UAE starting at AED 1,160
Follow US
Caffeine. Chaos. Content.
© Absolute Geeks Media FZE LLC 2014–2026.
Proudly made in Dubai, UAE ❤️
Contact · About · Editorial Policy · Privacy Policy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?