Skip to main content
  1. Home
  2. Computing
  3. News

Lenovo’s fingerprint scanner software is broken, update it today

Add as a preferred source on Google

There is a lot of bad news lately when it comes to the security of our PCs and other devices. All kinds of nefarious parties want to break into our machines and access our most vital personal and professional information. That is what makes recent advances in biometric security, such as fingerprint scanners and facial recognition, so welcome. It’s also what makes it so disturbing when there is a flaw in those systems, as was recently the case with Lenovo’s Fingerprint Manager Pro software.

Fingerprint Manager Pro is a Windows 7, 8, and 8.1 utility that enables the fingerprint scanner on certain Lenovo systems to match a user’s fingerprint and use it to log into the machine as well as to authenticate to websites without needing to type in a password. As Lenovo indicates in a recent support bulletin, versions of the utility older than 8.01.87 are vulnerable to attack thanks to a weak algorithm and a hard-coded password — leaving sensitive data accessible to any user with local non-administrative access to a machine.

Recommended Videos

It is important to note that Windows 10 machines are unaffected, thanks to Microsoft’s built-in fingerprint reader support. If you’re using Windows 10 Hello on a Lenovo system, therefore, you have nothing to worry about.

This isn’t the first time that Lenovo’s fingerprint software has suffered from a lapse in security. In early 2016, the Lenovo Fingerprint Manager and Touch Fingerprint Software utilities were vulnerable to a local privilege escalation that allows users to gain administrator rights when running applications.

Here is a list of the affected systems:

  • ThinkPad L560
  • ThinkPad P40 Yoga, P50s
  • ThinkPad T440, T440p, T440s, T450, T450s, T460, T540p, T550, T560
  • ThinkPad W540, W541, W550s
  • ThinkPad X1 Carbon (Type 20A7, 20A8), X1 Carbon (Type 20BS, 20BT)
  • ThinkPad X240, X240s, X250, X260
  • ThinkPad Yoga 14 (20FY), Yoga 460
  • ThinkCentre M73, M73z, M78, M79, M83, M93, M93p, M93z
  • ThinkStation E32, P300, P500, P700, P900

Go update the Lenovo Fingerprint Manager Pro utility today. You can download it here, and then install it as soon as you can to make sure your sensitive data remains protected. While you’re at it, you can check out all of Lenovo’s security advisories here to make sure you’re not exposed.

Mark Coppock
Former Computing Writer
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more
OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery
OpenAI

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet. This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking.

The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident.

Read more