Lenovo UEFI Security Flaws Affecting Over 100 Laptop Models Discovered, Company Issues Firmware Patches

Several models across the company’s IdeaPad, Legion, and Yoga portfolios are vulnerable to the flaws.

Advertisement
By David Delima | Updated: 20 April 2022 18:38 IST
Highlights
  • Lenovo issued a security advisory for the flaws on April 18
  • Affected Lenovo customers can download and install updated firmware
  • Lenovo laptops that are currently out of support will not be fixed

The Lenovo security vulnerabilities were responsibly disclosed to the company in October 2021

Photo Credit: Unsplash/ Buhai Alexandru Constantin

Lenovo has issued a security advisory related to three security vulnerabilities found on several laptops. The flaws affect over 100 Lenovo laptop models, across the company's IdeaPad, Legion, and Yoga portfolios. Using the vulnerabilities, an attacker might be able to disable the Unified Extensible Firmware Interface (UEFI) Secure Boot feature and execute arbitrary code on the laptop. The manufacturer has advised users with affected laptop models to update to the latest firmware for these devices from the official website, in order to stay protected.

Three vulnerabilities were discovered by ESET researchers and affect the UEFI Secure Boot feature, which is designed to verify and load trusted code when the laptop is booted. They were responsibly disclosed by the researchers to Lenovo in October 2021. The vulnerabilities were confirmed by the company in November and were assigned three CVEs (Common Vulnerabilities and Exposures) — CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972, and a security advisory was published by the manufacturer on Monday.

According to ESET, which has published a detailed technical analysis of the security flaws, two of the vulnerabilities — CVE-2021-3971 (SecureBackDoor), and CVE-2021-3972 (ChgBootDxeHook), were introduced by the company after two UEFI firmware drivers were accidentally included in the firmware. These drivers are only used when manufacturing the laptop and can be exploited by attackers to turn off the UEFI Secure Boot feature and disable protection for the flash memory chip which stores the UEFI firmware. Security software and other solutions on the operating system will be unable to detect these threats as they execute early in the boot process — before the operating system is loaded.

Advertisement

In order to bypass all the security features offered by Secure Boot, UEFI threats like the ones discovered by ESET, disable the secure mechanisms designed to load trusted code. According to the researchers, all the UEFI threats discovered in the wild including LoJax, MosaicRegressor, MoonBounce, ESPecter, FinSpy were able to bypass these mechanisms to execute their malicious code. Similar security flaws were also discovered in HP firmware, published by SentinelOne last month.

The researchers also found a third security flaw — or CVE-2021-3970 (LenovoVariableSmm), which could lead to arbitrary code execution in system management RAM (or SMRAM), with elevated privileges. In some cases, it can be used to activate the ChgBootDxeHook driver in order to disable UEFI Secure Boot feature, according to the researchers at ESET. All three security vulnerabilities discovered require the attacker to have local access to the device, but it is worth noting that Lenovo has assigned the flaws a “Medium” severity level in its advisory.

Advertisement

Over 100 consumer laptop models used by millions of users are affected by the security flaws, according to the researchers. Users who own devices that have active development support can download the latest firmware update for their laptop from Lenovo's Advisory website. However, several other affected devices won't be fixed as they have reached End of Development Support (EODS). However, these users can use a TPM-aware full-disk encryption to make disk data inaccessible if the UEFI Secure Boot configuration has been modified, according to the ESET researchers.


Asus India's Arnold Su joins this week's Orbital, the Gadgets 360 podcast, to talk about how the PC maker is planning to grow its presence in the country. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy F17 5G With 5,000mAh Battery Launched in India
  2. Oppo F31 Series Specifications Confirmed Ahead of India Launch
  3. Flipkart Big Billion Days: iPhone 16 Price to Drop to Its Lowest Ever
  4. Samsung Galaxy S25 FE Tipped to Go On Sale At This Price in India
  5. Flipkart BBD Deal: iPhone 16 Pro Max Under Rs. 90,000
  6. iPhone 14 Under Rs. 40,000: Flipkart's Big Billion Days Deal Revealed
  7. Vivo X300 Series Launch Date Leaked: Here's When It Might Debut
  8. OTT Releases This Week: Coolie, Saiyaara, a Tamannaah Bhatia Web Series
  9. HMD Vibe 5G Launched in India Alongside HMD 101 4G and HMD 102 4G
  10. Samsung Galaxy Buds 3 FE Launched in India With ANC, Galaxy AI Features
  1. Gemini Is Reportedly Expanding Its Split-Screen Switch Feature to Candybar Android Phones
  2. Motorola Pad 60 Neo Launched in India With 7,040mAh Battery, 2.5K 11-Inch Display: Price, Features
  3. Cyberpunk 2077 Gets Patch 2.31, Featuring Improvements to AutoDrive, Photo Mode and More
  4. Samsung Galaxy Tab S10 Lite Launched in India With Exynos 1380 SoC: Price, Specifications
  5. Samsung Galaxy Buds 3 FE Launched in India With ANC, Galaxy AI Features: Price, Specifications
  6. Vivo X300 Series Launch Date, Camera Specifications Leaked
  7. Gmail Adds Purchases Tab to Simplify Online Order Tracking Ahead of Festive Sale Season
  8. WhatsApp for Android Testing Message Threads for Easier Group Chat Organisation
  9. Apple Issues Spyware Threat Notifications to Users in France
  10. Nothing Ear 3 First Look Is Here, Design Reveals Mysterious Talk Button
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.