Readers like you keep news free for everyone.

More than 5,000 readers have already pitched in to keep free access to The Journal.

For the price of one cup of coffee each week you can help keep paywalls away.

Support us today
Not now
Thursday 7 December 2023 Dublin: 11°C
AP Photo/Ron Harris

Lenovo computers have another 'massive security risk'

A patch for the issue has already been released, but users need to update manually.

Updated: 12:55

THREE MONTHS AGO, Lenovo got into trouble over Superfish, a software add-on which was to bring up extra ads but instead carried a serious security flaw, allowing any hacker to carry out man-in-the-middle attacks remotely.

Now another major security flaw has emerged, allowing hackers to bypass security checks, replace Lenovo software with their own and issue commands remotely.

The security firm IOActive discovered the flaw back in February and informed Lenovo of the problem who then issued a patch at the beginning of April.

Describing it as a “massive security risk”, one issue would allow basic user profiles to be changed so they gain admin-level access to a PC, allowing them to run any programmes or commands they wish.

Another issue would allow remote attackers to replace trusted Lenovo applications with their own malicious versions by creating fake certificates for files.

While a patch has been issued, users still need to download the update themselves so if you have System Update or earlier on your Lenovo computer, you need to update it otherwise you’re at risk.

Lenovo issued a statement relating to the security flaw and patch.

Lenovo’s development and security teams worked directly with IOActive regarding their System Update vulnerability findings, and we value their expertise in identifying and responsibly reporting them.Lenovo released an updated version of System Update on April 1st which resolves these vulnerabilities and subsequently published a security advisory in coordination with IOActive at:

Existing installations of System Update will prompt the user to automatically install the updated version when the application is run. Alternatively, users may manually update System Update as described in the security advisory.  Lenovo recommends that all users update System Update to eliminate the vulnerabilities reported by IOActive.

Read: ‘Dave was my rock’: Sheryl Sandberg takes to Facebook to remember her husband >

Read: Skype may be about to get a name change >

Your Voice
Readers Comments
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.