Skip to main content

Your Lenovo laptop may have a serious security flaw

Lenovo laptop on desk
Vlad Bagacian/Unsplash

Users of older Lenovo laptops should beware of a security flaw that may affect their PCs, particularly if their laptops are still running a program called Lenovo Solution Center.

According to Laptop Magazine, security researchers at Pen Test Partners have discovered a security vulnerability that could effectively “hand admin privileges over to hackers or malware.” And since the flaw affects Lenovo laptops that came pre-installed with the Lenovo Solution Center program, millions of older Lenovo laptops could be affected by the flaw. This is because Lenovo laptops had the program installed for years, from 2011 all the way to November 2018.

Pen Test Partners published its own post about the flaw on Thursday, August 22. In the post, PTP described the flaw as a “privilege escalation vulnerability” which allows the use of a DACL (discretionary access control list) overwrite bug and a “hardlink” (pseudo) file to let “the low-privileged user take full control of a file they shouldn’t normally be allowed to. This can, if you’re clever, be used to execute arbitrary code on the system with Administrator or System privileges.”

Lenovo issued its own security warning about the flaw on Tuesday, August 20. In this statement, Lenovo said that the flaw affected devices running Lenovo Solution Center version 03.12.003 and recommend that Lenovo users should go ahead and uninstall Lenovo Solution Center (which is no longer supported) and “migrate to Lenovo Vantage or Lenovo Diagnostics.” Lenovo’s security warning statement also included instructions on how to uninstall Lenovo Solution Center for devices running Windows 10, Windows 8, and Windows 7.

It’s also worth noting that in its post, Pen Test Partners also noted a discrepancy involving the actual end-of-life date for the Lenovo Solution Center program:

“Whilst Lenovo were responsive to my disclosure, when we reported this to them back in May, their LSC download page noted that the tool went end of life in November 2018…But just after their disclosure went out, we noticed they had changed the end-of-life date to make it look like it went end of life even before the last version was released. Their own vulnerability advisory states: ‘Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or Lenovo Diagnostics in April 2018.’… yet the last release of LSC was on 15th October 2018 … Could it be a typo, or were Lenovo trying to cover their tracks? Misleading and strange.”

The Register asked Lenovo about the end-of-life date discrepancy and the laptop manufacturer responded with the following statement:

“It’s often the case for applications that reach end of support that we continue to update the applications as we transition to new offerings is to ensure customers that have not transitioned, or choose not to, still have a minimal level of support, a practice that is not uncommon in the industry.”

Digital Trends has reached out to Lenovo for comment, and we’ll update this article once we receive a response.

Editors' Recommendations

Anita George
Anita has been a technology reporter since 2013 and currently writes for the Computing section at Digital Trends. She began…
Buying a gaming laptop? These are the brands to trust
Diablo 4 running on the Alienware x16.

You may know what the best gaming laptops are, but what if you'd like to explore even more options? Nearly every laptop brand has some gaming angle -- even MacBooks are on the gaming train these days -- but it's hard to know which to trust. We can help you narrow down your options with this list of the best laptop brands.

We review dozens of gaming laptops every year, and there are some brands that consistently deliver high-quality laptops that balance performance, price, build quality, and extra features. If you're shopping for a gaming laptop, these are the brands that should come to mind first.
Lenovo

Read more
The upcoming Windows ARM laptops may have surprisingly powerful GPUs
A laptop and a camera on a table with a Qualcomm logo on the screen.

The next generation of ARM-based laptops and tablets with the new Snapdragon X Elite system-on-a-chip (SoC) won't be coming for a few more months, but new benchmarks already show its potential power in an important way. The results are surprising, and they show that Qualcomm's new ARM chip has as powerful a GPU as Intel's latest Core Ultra CPUs.

All of these new tests, which were initially spotted by WccfTech, were performed by Turkish YouTuber Erdi Özüağ in some pretty specific scenarios. Özüağ was able to push beyond the benchmark suites we've seen thus far and run the Proycon benchmark, as well as 3DMark and tests in Visual Studio Code and 7-Zip. He used a device with Qualcomm's reference design, as well as a laptop with an Intel Core Ultra 7 155H CPU. The device with the Qualcomm chip was running at 28 watts of power.

Read more
Your American Express credit card info may have been hacked
WWDC

American Express has put out a data breach advisory after third-party merchants experienced a hacking incident targeting its payment hardware, as reported by Bleeping Computer.

The financial services company detailed that the breach occurred in Massachusetts and is associated with an "American Express Travel Related Services Company." It resulted in several merchants suffering "unauthorized access to its system." Customers' credit card information, including account numbers, names, and card expiration data, may have been exposed in the process.

Read more