Critical Flaws Found in Laptops From Several Major Manufacturers: Report

Advertisement
By Ketan Pratap | Updated: 1 June 2016 18:46 IST
Highlights
  • The researchers investigated 10 laptops from popular OEMs.
  • Software update tools on laptops contained at least one critical flaw.
  • HP, Dell, and Lenovo have already released fixes for vulnerabilities.

Duo Labs, the research team at Duo Security, has discovered new security vulnerabilities in the software update tools preloaded on laptops of some popular brands. In its new published study 'Out-of-Box Exploitation: A Security Analysis of OEM Updaters', Duo Labs found that laptops from HP, Dell, Acer, Asus, and Lenovo carried security vulnerabilities right out-of-the-box that if exploited could allow attackers to take over the system in just 10 minutes.

The research team noted, "Every OEM we looked at included one (or more) [vulnerabilities] with their default configuration." The team found 12 different software vulnerabilities in the software update tools that come preloaded on laptops from HP, Dell, Acer, Asus, and Lenovo.

The researchers investigated the Lenovo Flex 3, HP Envy, HP Stream x360 (Microsoft Signature Edition), HP Stream (UK version), Lenovo G50-80 (UK version), Acer Aspire F15 (UK version), Dell Inspiron 14 (Canada version), Dell Inspiron 15-5548 (Microsoft Signature Edition), Asus TP200S, and Asus TP200S (Microsoft Signature Edition).

Advertisement

Steve Manzuik, Duo Security's Director of Security Research explained to IBTimes UK, "Short of explicitly disabling updaters and removing Original Equipment Manufacturer [OEM] components altogether, the end user can do very little to protect themselves from the vulnerabilities created by OEM update components. In general you have to be a tech person to understand there's a problem and then know how to fix it. You have to know to go to the manufacturer's website and know how to download and install the software. We knew these laptops were being bought by people who aren't tech people."

Talking about the five OEMs, Manzuik said that Acer and Asus were the "worst." Manzuik said, "With Asus, there were two different vulnerabilities. This one had code execution that was quite obvious and easy to exploit - it literally took less than 10 minutes to attack the system using that vulnerability."

Duo Labs also suggested some steps for users to safeguard from preloaded software vulnerabilities including wiping any OEM system, and reinstalling a clean and bloatware-free copy of Windows before the system is used. The research team also suggests identifying any unnecessary software and disabling or uninstalling it.

Advertisement

"Dell, HP and Lenovo vendors (in specific cases) appeared to perform more security due diligence when compared to Acer and Asus," added the study.

Soon after Duo Labs reached out to the OEMs, many fixed the vulnerabilities by releasing fixes. According to the research team, HP, Dell, and Lenovo released the fixes. Acer and Asus acknowledged the vulnerabilities and will soon release a fix.

Advertisement

This is not the first time popular laptop OEMs have been identified carrying software vulnerabilities preloaded as previously cases such as the Superfish fiasco where Lenovo was caught installing adware on many of its PCs as well as eDellRoot where Dell was reported to be shipping its systems with a self-signed digital certificate that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Acer, Asus, Bloatware, Dell, HP, Laptops, Lenovo, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Launch Details Likely to Be Announced on October 17
  2. iQOO 15 With Snapdragon 8 Elite Gen 5 SoC to Launch in India in November
  3. Google Offers Up to 2TB of Storage Across Gmail and Photos for Rs. 11
  4. Vivo Announces OriginOS 6 for Vivo and iQOO Handsets Globally
  5. Redmi Note 15 Series India Launch Timeline, Price and Features Leaked
  6. Honor's Robot Phone With a Pop-Up Camera Will Debut at MWC 2026
  7. Realme GT 8 Pro Colourways Revealed; Realme GT 8 to Run on This Chipset
  8. Oppo Find X9 Series, Oppo Pad 5 Launching Today: All You Need to Know
  9. Honor Magic 8, Magic 8 Pro With Snapdragon 8 Elite Gen 5 Launched: See Price
  10. iPad Pro With M5 Chip, OLED Display Launched in India at This Price
  1. Reliance Jio, Aptos to Launch Blockchain Rewards for 500 Million Users
  2. Apple Executive Leading Siri Revamp Project Reportedly Snagged by Meta
  3. Samsung Galaxy S26 Edge Reportedly Scrapped; Galaxy S26 Lineup Could Comprise Three Models
  4. Redmi Note 15 Pro+, Note 15 Pro India Launch Timeline, Price and Specifications Leaked
  5. Asus ROG Xbox Ally X Goes on Sale in India Alongside ROG Xbox Ally: Price, Features
  6. Google One Diwali Offer Provides Up to 2TB of Google Drive Storage for Just Rs. 11: See Offers
  7. Google Releases Veo 3.1 Video Model With Improved Controls and Longer Video Durations
  8. Silent Hill 2 Remake, Until Dawn and Yakuza: Like a Dragon Coming to PS Plus Game Catalog in October
  9. Bitcoin Price Steadies Above $111,000 Amidst Ongoing Trade Tensions
  10. Honor Launches Android 16-Based MagicOS 10 With AI, Connectivity Upgrades: Eligible Devices, Rollout Schedule
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.