Critical 'ThinkPwn' Security Flaw Found in Lenovo Laptops; Other Manufacturers Potentially Vulnerable

Advertisement
By Jamshed Avari | Updated: 4 July 2016 22:38 IST
Highlights
  • Developer Dmytro Oleksiuk posted details of the flaw to GitHub
  • Lenovo has pinned the blame on Intel and outside contractors
  • One Twitter user has claimed that his HP laptop is also affected
Lenovo has owned up to the existence of a critical security vulnerability in the firmware of many of its laptops. After teasing it on Twitter on June 29, developer and self-described "unethical hacker" Dmytro Oleksiuk posted details of the vulnerability on GitHub. Commentators have quickly dubbed the issue 'ThinkPwn' although it now seems to be common to other hardware vendors.

According to Oleksiuk, the flaw affects a large number of Lenovo's ThinkPad models going back several years. He claimed to have verified it on a ThinkPad X220, which launched in 2011. He has provided snippets of code and instructions on his GitHub post so that others can detect the vulnerability on systems they have access to.

The flaw allows remote attackers to disable write protection on a device's firmware and gain access to the System Management Mode, which is intended to be a secure environment for approved code to be run in. This must be done by physically accessing the device, which at least limits the scope of the attack. However, once that is done, an attacker can remotely disable the Secure Boot feature found in most modern UEFI BIOSes which verifies the integrity of the OS. Rootkits can then be introduced into a compromised system, allowing attackers to spy on them and take control of them remotely. Software security features designed to protect a person or company's credentials can also be compromised.

Advertisement

The company has issued an initial security advisory, LEN-8324, in which it says it is working on a solution as quickly as possible. According to the statement, Lenovo tried to contact the independent researcher who claimed knowledge of the problem, but he published it without any coordination. The statement goes on to state that Lenovo has identified vulnerable parts of its System Management Mode code, but pins the blame on "at least one of our Independent BIOS Vendors (IBVs)" - software companies to which Lenovo outsources the development of its custom BIOS firmware - as well as Intel, which created the common code base that IBVs work with.

Oleksiuk has tweeted that Lenovo only demanded that he not release his findings, and statements on his GitHub accuse the company of "copy-pasting" Intel's reference code for 8-series chipsets. He also makes a passing note that the code could have been crafted intentionally for use as a backdoor. This heavily suggests that Lenovo isn't the only company whose products are affected by the flaw, and at least one Twitter user has tweeted Oleksiuk with purported evidence that at least one HP laptop model is vulnerable.

Advertisement

Lenovo says it is working to identify the author of that specific piece of code, implying that it was not a mistake but put in purposefully. Functions such as remote administration have been known to expose controls of computer systems to unintended people either due to security lapses or poor judgment.

Lenovo has had several security problems of late, including revelations that it deliberately shipped PCs with spyware as well as easily compromised adware and other bloat preinstalled.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Fitbit Air Spotted on Amazon India Ahead of Official Launch
  2. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  3. Tecno Camon 50 Ultra 5G Sale Begins in India Today
  4. Samsung Galaxy Watch 9 Leak Reveals Major Chipset Upgrade Before Galaxy Unpacked
  5. Samsung Galaxy Z Fold 8 Fresh Renders Leaked Online Just Ahead of Launch
  6. X App Revamped for Android With These Visual, Performance Upgrades
  1. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  2. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  3. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  4. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  5. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  6. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
  7. Xiaomi Pad 9 Could Launch Soon With a Bigger Battery, Certification Listing Suggests: Expected Specifications
  8. Redmi 17 4G EPREL Certification Listing Gives an Early Look at Its Specifications
  9. Tecno Camon 50 Ultra 5G Goes on Sale in India With Dimensity 7400 Ultimate SoC: Price, Offers
  10. Redmi Watch 6 Active, Watch 6 Lite Price, Key Specifications, and Other Details Leaked Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.