Lenovo, Dell, Toshiba PC Vulnerability Exposes Millions to Attack: Report

Advertisement
By Manish Singh | Updated: 7 December 2015 16:37 IST

Some laptops and PCs from Lenovo, Dell, and Toshiba are reportedly vulnerable to attack. A vulnerability has been found in the suite of apps that these leading manufacturers pre-install on their devices. Millions of users are estimated to be affected.

A security professor who goes by the alias slipstream/ RoL has posted a proof-of-concept to demonstrate the vulnerability in the bloatware shipped by Lenovo, Dell, and Toshiba that can allow attackers to run malware at the system level.

The vulnerability can be exploited when a user visits a specially-crafted webpage. When a victim with an affected system visits the page, an attacker is able to run code with full system privileges on the system. From this point forward, an attacker can install malware and spyware on the system.

Advertisement

For Lenovo users, the vulnerability resides in Lenovo Solution Center, a program that is designed to let users know the system's health, security, and network status. The security researcher noted that if these devices are already affected with malicious apps, an attacker doesn't even need to visit any website to get attacked.

Advertisement

CERT, a non-profit United States federally funded research and development centre, wrote the following in an advisory. "By convincing a user who has launched the Lenovo Solution Center to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with SYSTEM privileges. Additionally, a local user can execute arbitrary code with SYSTEM privileges." The organisation further urges users to uninstall Lenovo System Center.

Lenovo has acknowledged the bug in an advisory it posted last week. "We are urgently assessing the vulnerability report and will provide an update and applicable fixes as rapidly as possible. Additional information and updates will be posted to this security advisory page as they become available."

Advertisement

A similar vulnerability has been found in Dell System Detect program. The discovery of the program comes less than a month after the US company was found to have rogue certificate on its computers. Toshiba bundles Service Station tool on its system that can be abused in a similar fashion.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  2. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  3. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  4. Realme P4x 5G Launch Today: Know Price in India, Specs and More
  5. Samsung's One UI 8.5 Changelog Leak Hints at Imminent Beta Release
  6. Best 5G Smartphones Under Rs 10,000 in India: Galaxy M06 5G, Poco M7, More
  7. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  8. Pariah OTT Release: Vikram Chatterjee's Dog-Drama Lands on OTT Soon
  9. Samsung Teases Its Exynos 2600 Chip That May Debut on the Galaxy S26 Series
  1. Realme P4x 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Pariah OTT Release: Vikram Chatterjee’s Heart-Wrenching Stray Dog Thriller Set for OTT Debut
  3. Dies Irae OTT Release: When, Where to Watch Pranav Mohanlal's Malayalam Horror Thriller Online
  4. A Nearby Planet May Have Formed the Moon Following a Collision With Early Earth: Study
  5. Netflix’s Gritty Frontier Drama The Abandons to Begin Streaming Soon: All You Need to Know
  6. Superman OTT Release Date Announced: Everything You Need to Know About Clark Kent's Latest Adventure
  7. International Space Station Makes History As Eight Visiting Spacecraft Simultaneously Dock
  8. Dulquer Salmaan’s Kaantha Set for OTT Debut: When and Where to Watch 1950's Period Drama Online?
  9. Motorola Edge 70 India Launch Date Leaked; Indian Variant Said to Feature Bigger Battery, Slim Design
  10. SpaceX Adds 29 New Starlink Satellites in Successful Falcon 9 Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.