Critical Flaws Found in Laptops From Several Major Manufacturers: Report

Advertisement
By Ketan Pratap | Updated: 1 June 2016 18:46 IST
Highlights
  • The researchers investigated 10 laptops from popular OEMs.
  • Software update tools on laptops contained at least one critical flaw.
  • HP, Dell, and Lenovo have already released fixes for vulnerabilities.

Duo Labs, the research team at Duo Security, has discovered new security vulnerabilities in the software update tools preloaded on laptops of some popular brands. In its new published study 'Out-of-Box Exploitation: A Security Analysis of OEM Updaters', Duo Labs found that laptops from HP, Dell, Acer, Asus, and Lenovo carried security vulnerabilities right out-of-the-box that if exploited could allow attackers to take over the system in just 10 minutes.

The research team noted, "Every OEM we looked at included one (or more) [vulnerabilities] with their default configuration." The team found 12 different software vulnerabilities in the software update tools that come preloaded on laptops from HP, Dell, Acer, Asus, and Lenovo.

Advertisement

The researchers investigated the Lenovo Flex 3, HP Envy, HP Stream x360 (Microsoft Signature Edition), HP Stream (UK version), Lenovo G50-80 (UK version), Acer Aspire F15 (UK version), Dell Inspiron 14 (Canada version), Dell Inspiron 15-5548 (Microsoft Signature Edition), Asus TP200S, and Asus TP200S (Microsoft Signature Edition).

Steve Manzuik, Duo Security's Director of Security Research explained to IBTimes UK, "Short of explicitly disabling updaters and removing Original Equipment Manufacturer [OEM] components altogether, the end user can do very little to protect themselves from the vulnerabilities created by OEM update components. In general you have to be a tech person to understand there's a problem and then know how to fix it. You have to know to go to the manufacturer's website and know how to download and install the software. We knew these laptops were being bought by people who aren't tech people."

Advertisement

Talking about the five OEMs, Manzuik said that Acer and Asus were the "worst." Manzuik said, "With Asus, there were two different vulnerabilities. This one had code execution that was quite obvious and easy to exploit - it literally took less than 10 minutes to attack the system using that vulnerability."

Duo Labs also suggested some steps for users to safeguard from preloaded software vulnerabilities including wiping any OEM system, and reinstalling a clean and bloatware-free copy of Windows before the system is used. The research team also suggests identifying any unnecessary software and disabling or uninstalling it.

Advertisement

"Dell, HP and Lenovo vendors (in specific cases) appeared to perform more security due diligence when compared to Acer and Asus," added the study.

Soon after Duo Labs reached out to the OEMs, many fixed the vulnerabilities by releasing fixes. According to the research team, HP, Dell, and Lenovo released the fixes. Acer and Asus acknowledged the vulnerabilities and will soon release a fix.

Advertisement

This is not the first time popular laptop OEMs have been identified carrying software vulnerabilities preloaded as previously cases such as the Superfish fiasco where Lenovo was caught installing adware on many of its PCs as well as eDellRoot where Dell was reported to be shipping its systems with a self-signed digital certificate that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Acer, Asus, Bloatware, Dell, HP, Laptops, Lenovo, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1.  Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  2. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display
  3. Redmi Turbo 5 Tipped to Launch in India on This Date
  4. Lumio Launches 55-Inch Variants of Vision 9 (2026), Vision 7 (2026) in India
  5. Android Phones Can Now Detect Fake Calls to Alert Users in Advance
  6. Realme P4R 5G India Launch Date, Design and Key Specifications Revealed
  7. Samsung Galaxy Z Fold 8 Ultra Tipped to Get Battery, Charging Upgrades
  1. UK's FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsor Risks
  2. Vivo X500 Pro Max Display and Battery Details Surface Online in Early Leak; Largest Model Said to Feature 6.85-Inch Screen
  3. Google Introduces Fake Call Detection for Android Phones to Curb Call Spoofing Attacks
  4. Google Rolls Out Gemini Thinking Levels Across Platforms With 'Extended' Thinking Mode for All Users
  5. Samsung Galaxy A27 Reportedly Bags US FCC Certification Ahead of Anticipated Launch
  6. NYDFS, European Banking Authority Join Forces to Oversee, Monitor Stablecoin Activities
  7. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  8. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  9. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  10. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.