Lenovo, Dell, Toshiba PC Vulnerability Exposes Millions to Attack: Report

Advertisement
By Manish Singh | Updated: 7 December 2015 16:37 IST

Some laptops and PCs from Lenovo, Dell, and Toshiba are reportedly vulnerable to attack. A vulnerability has been found in the suite of apps that these leading manufacturers pre-install on their devices. Millions of users are estimated to be affected.

A security professor who goes by the alias slipstream/ RoL has posted a proof-of-concept to demonstrate the vulnerability in the bloatware shipped by Lenovo, Dell, and Toshiba that can allow attackers to run malware at the system level.

The vulnerability can be exploited when a user visits a specially-crafted webpage. When a victim with an affected system visits the page, an attacker is able to run code with full system privileges on the system. From this point forward, an attacker can install malware and spyware on the system.

Advertisement

For Lenovo users, the vulnerability resides in Lenovo Solution Center, a program that is designed to let users know the system's health, security, and network status. The security researcher noted that if these devices are already affected with malicious apps, an attacker doesn't even need to visit any website to get attacked.

CERT, a non-profit United States federally funded research and development centre, wrote the following in an advisory. "By convincing a user who has launched the Lenovo Solution Center to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with SYSTEM privileges. Additionally, a local user can execute arbitrary code with SYSTEM privileges." The organisation further urges users to uninstall Lenovo System Center.

Lenovo has acknowledged the bug in an advisory it posted last week. "We are urgently assessing the vulnerability report and will provide an update and applicable fixes as rapidly as possible. Additional information and updates will be posted to this security advisory page as they become available."

Advertisement

A similar vulnerability has been found in Dell System Detect program. The discovery of the program comes less than a month after the US company was found to have rogue certificate on its computers. Toshiba bundles Service Station tool on its system that can be abused in a similar fashion.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme P4 Power 5G Will Launch in India
  2. Vivo X200T With Zeiss Cameras to Launch in India on This Date
  3. Motorola Edge 70 Fusion Leak Reveals Full Specifications Ahead of Launch
  4. Redmi Note 15 Pro Series Might Launch in India With These Storage Options
  5. Xiaomi 18 Series Could Get Periscope Telephoto Lens as Standard
  6. Google Pixel 10a Leak Suggests No Price Hike Over Pixel 9a
  7. Oppo A6 5G Launched in India With 7,000mAh Battery at This Price
  8. New Dark Matter Simulation Could Change How Galaxies Are Thought to Evolve
  9. Sony to Cede Control of Bravia TVs to China's TCL Electronics
  10. Ai+ Targets 5X Growth, Plans 5G, Flip Phones, and a Connected Ecosystem
  1. New Dark Matter Simulation Could Change How Galaxies Are Thought to Evolve
  2. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  3. Sony to Cede Control of Bravia TVs to China’s TCL Electronics
  4. Adobe Premiere Integrated With AI-Powered Firefly Platform; New After Effects Features Rolling Out
  5. Samsung Upgrades Bixby With Perplexity-Powered AI Features, Takes Page Out of Apple’s Playbook
  6. Google Reportedly Working On New Live Features and Agentic Mode for Gemini Assistant
  7. Redmi Note 15 Pro+, Redmi Note 15 Pro RAM and Storage Options, Key Specifications Leaked Ahead of India Launch
  8. Eddington Arrives on OTT: What You Need to Know About Joaquin Phoenix and Pedro Pascal Starrer Thriller
  9. Red Magic 11 Air Launched With Snapdragon 8 Elite, RedCore R4 Gaming Chip and 7,000mAh Battery
  10. Nikosh Chhaya Season 2 OTT Release Date Revealed: Know When and Where to Watch This Bengali Horror Series
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.