Critical Flaws Found in Laptops From Several Major Manufacturers: Report

Advertisement
By Ketan Pratap | Updated: 1 June 2016 18:46 IST
Highlights
  • The researchers investigated 10 laptops from popular OEMs.
  • Software update tools on laptops contained at least one critical flaw.
  • HP, Dell, and Lenovo have already released fixes for vulnerabilities.

Duo Labs, the research team at Duo Security, has discovered new security vulnerabilities in the software update tools preloaded on laptops of some popular brands. In its new published study 'Out-of-Box Exploitation: A Security Analysis of OEM Updaters', Duo Labs found that laptops from HP, Dell, Acer, Asus, and Lenovo carried security vulnerabilities right out-of-the-box that if exploited could allow attackers to take over the system in just 10 minutes.

The research team noted, "Every OEM we looked at included one (or more) [vulnerabilities] with their default configuration." The team found 12 different software vulnerabilities in the software update tools that come preloaded on laptops from HP, Dell, Acer, Asus, and Lenovo.

The researchers investigated the Lenovo Flex 3, HP Envy, HP Stream x360 (Microsoft Signature Edition), HP Stream (UK version), Lenovo G50-80 (UK version), Acer Aspire F15 (UK version), Dell Inspiron 14 (Canada version), Dell Inspiron 15-5548 (Microsoft Signature Edition), Asus TP200S, and Asus TP200S (Microsoft Signature Edition).

Advertisement

Steve Manzuik, Duo Security's Director of Security Research explained to IBTimes UK, "Short of explicitly disabling updaters and removing Original Equipment Manufacturer [OEM] components altogether, the end user can do very little to protect themselves from the vulnerabilities created by OEM update components. In general you have to be a tech person to understand there's a problem and then know how to fix it. You have to know to go to the manufacturer's website and know how to download and install the software. We knew these laptops were being bought by people who aren't tech people."

Advertisement

Talking about the five OEMs, Manzuik said that Acer and Asus were the "worst." Manzuik said, "With Asus, there were two different vulnerabilities. This one had code execution that was quite obvious and easy to exploit - it literally took less than 10 minutes to attack the system using that vulnerability."

Duo Labs also suggested some steps for users to safeguard from preloaded software vulnerabilities including wiping any OEM system, and reinstalling a clean and bloatware-free copy of Windows before the system is used. The research team also suggests identifying any unnecessary software and disabling or uninstalling it.

Advertisement

"Dell, HP and Lenovo vendors (in specific cases) appeared to perform more security due diligence when compared to Acer and Asus," added the study.

Soon after Duo Labs reached out to the OEMs, many fixed the vulnerabilities by releasing fixes. According to the research team, HP, Dell, and Lenovo released the fixes. Acer and Asus acknowledged the vulnerabilities and will soon release a fix.

Advertisement

This is not the first time popular laptop OEMs have been identified carrying software vulnerabilities preloaded as previously cases such as the Superfish fiasco where Lenovo was caught installing adware on many of its PCs as well as eDellRoot where Dell was reported to be shipping its systems with a self-signed digital certificate that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Acer, Asus, Bloatware, Dell, HP, Laptops, Lenovo, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi Pad 8 Launches Globally Alongside Xiaomi Tag: Price, Features
  1. Xiaomi Pad 8 Launched Globally With 11.2-inch LCD Screen, Snapdragon 8s Gen 4 Chip: Price, Specifications
  2. Xiaomi 17 Ultra Launched Globally With 200-Megapixel Persicope Camera Alongside Xiaomi 17: Price, Specifications
  3. NASA’s ESCAPADE Mission to Study Space Weather Between Earth and Mars
  4. Huawei Watch GT Runner 2 Launched Globally With Intelligent Marathon Mode, 3D Floating Antenna: Price, Features
  5. Honor Magic V6 With Nearly Creaseless Inner Display Teased By Product Manager Ahead of MWC
  6. Sony Said to Be 'Backing Away' From Launching Its Single-Player Games on PC
  7. Android 17 Beta 2 Released: Lets Users Create Bubble for Any App, Expands SMS OTP Protection
  8. Ultrahuman Ring Pro Launched With 15-Day Battery Life, Jade Biointelligence AI: Price, Features
  9. Monarch: Legacy of Monsters Season 2 Now Streaming on Apple TV+: Everything You Need to Know
  10. Vladimir OTT Release Date: When and Where to Watch Rachel Weisz Starrer Thriller Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.