Lenovo Fingerprint Manager Software on Older Windows Machines Is Vulnerable to Hacks

Advertisement
By Jagmeet Singh | Updated: 30 January 2018 11:42 IST
Highlights
  • Lenovo acknowledges the existence of the vulnerability
  • The vulnerability exists in the company's Fingerprint Manager Pro
  • Windows 10 devices remain unaffected

A critical vulnerability has emerged on over three dozen Lenovo systems that could let hackers bypass fingerprint scanner and gain access to existing Windows credentials. Machines that are affected by the security loophole includes several ThinkPad, ThinkStation, and ThinkCentre systems. Lenovo has acknowledged the flaw and released an update to its Fingerprint Manager Pro as a part of its mitigation strategy.

The latest vulnerability, which the company marked with high severity, exists in the Lenovo Fingerprint Pro utility that is specifically designed for Lenovo ThinkPad, ThinkStation, and ThinkCentre running Windows 7, Windows 8, and Windows 8.1. The scope of the vulnerability is quite wide as hackers could achieve access to Windows login credentials and fingerprint data. Nevertheless, it remains unaffected on systems with Windows 10 as the new operating system uses Microsoft's built-in fingerprint reader support through Windows Hello.

"Sensitive data stored by Lenovo Fingerprint Manager Pro, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system it is installed in," Lenovo said in a security advisory.

Advertisement

The list of models that are affected with the flaw includes the Lenovo ThinkPad L560, ThinkPad P40 Yoga, ThinkPad P50s Yoga, ThinkPad T440, ThinkPad T440p, ThinkPad T440s, ThinkPad T450, ThinkPad T450s, ThinkPad T460, ThinkPad T540p, ThinkPad T550, ThinkPad T560, ThinkPad W540, ThinkPad W541, ThinkPad W550s, ThinkPad X1 Carbon (Type 20A7, 20A8), ThinkPad X1 Carbon (Type 20BS, 20BT), ThinkPad X240, ThinkPad X240s, ThinkPad X250, ThinkPad X260, ThinkPad Yoga 14 (20FY), ThinkPad Yoga 460, ThinkCentre M73, ThinkCentreM73z, ThinkCentre M78, ThinkCentre M79, ThinkCentre M83, ThinkCentre M93p, ThinkCentre M93z, ThinkStation E32, ThinkStation P300, ThinkStation P500, ThinkCentre P700, and ThinkCentre P900.

Advertisement

Importantly, the vulnerability can only be exploited with local access. This means that the hacker needs to bypass the weak security layer in person, instead of using any remote access channel.

As of January 25, Lenovo has released Fingerprint Manager Pro version 8.01.87 to mitigate the vulnerability.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera
  2. Apple Finally Releases iOS 26.2 Update for iPhone With These Features
  3. Supernatural Thriller Jatadhara Now Streaming on OTT: All the Details
  1. Kepler and TESS Discoveries Help Astronomers Confirm Over 6,000 Exoplanets Orbiting Other Stars
  2. Supernatural Thriller Jatadhara Arrives on OTT: Where to Watch Sonakashi Sinha-Starrer Film Online?
  3. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera, 4K Video Recording Support
  4. Rocket Lab Clears Final Tests for New 'Hungry Hippo' Fairing on Neutron Rocket
  5. Apple Rolls Out iOS 26.2 Update for iPhone With Liquid Glass Customisation, Changes to Apple Music, and More
  6. Aaromaley Now Streaming on JioHotstar: Everything You Need to Know About This Tamil Romantic-Comedy
  7. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  8. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  9. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  10. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.