Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. Web
  5. News

Lenovo issues update fixing software vulnerabilities on many of its computers

Add as a preferred source on Google

Information security company Trustwave Holdings provided Digital Trends with an early glimpse into an upcoming blog set to be published on Friday afternoon, stating that the firm has discovered multiple vulnerabilities in the Lenovo Solution Center software that’s pre-installed on most Lenovo products including ThinkPad, ThinkPad Tablet, ThinkCentre and ThinkStation, IdeaCentre, and select Ideapad laptops.

The report was provided by Trustwave’s Martin Rakhmanov, and reveals that the vulnerabilities in this specific Lenovo software suite allows “unprivileged” local users to run arbitrary code with the highest system-level privileges. Typically, only the administrator has full system access, but the problem allows any non-administrator account on the computer to be used to hack the system.

Recommended Videos

The exploits were discovered in Lenovo Solution Center version 2.8.006 but affects all versions prior to 3.3.0002. Hackers can simply open up the Command Prompt to launch the Lenovo Solution Center service, or launch the Lenovo System Health and Diagnostics application through the Control Panel. After that, the hackers can enter a specific URL in any web browser and pull up the Device Manager running as LocalSystem instead of the current non-administrative user.

With Device Manager now loaded, hackers can install a new “driver” that will execute whatever code they choose in user mode or kernel mode. However, the report said that the kernel mode drivers must be signed by default whereas the user mode drivers can run as a LocalService account. To execute the code, hackers must create a “dummy” driver with an INF file that points back to a malicious DLL file stored on the hard drive.

That said, hackers merely use the “Add legacy hardware” option in Device Manager, select “Install the hardware that I manually select from a list (Advanced),” then “Show All Devices,” and finally “Have Disk.” The hackers then locate the INF file and agree to install non-verified driver software.

According to the report, Trustwave contacted Lenovo about the issue with Lenovo Solution Center on January 11. Subsequently, a patch was released by Lenovo on April 26. Lenovo has provided a warning page here that explains the situation and adds that hackers can attack the vulnerable PC remotely as well. The company also points out that while Lenovo Solution Center may not be actively running on the screen, the vulnerable backend service process continues to run.

“A cross-site request forgery (CSRF) vulnerability exists that may allow exploitation of these vulnerabilities if a user opens a malicious web site or crafted URL while the LSC backend service is running on a user’s machine.  The user’s computer may still be vulnerable even if the LSC user interface is not running,” the warning current states.

The release history shows that 3.3.002 is the latest version of Lenovo Solution Center. Customers are encouraged to upgrade the software by clicking “Yes” or “Update Now” when prompted on the program’s user interface, depending on the version currently installed.

As previously stated, Lenovo installs this software on most of its PCs. The suite serves as a hub for monitoring the system’s health and security such as firewall status, antivirus status, battery health, and more. It joins a number of other software components Lenovo loves to install like Lenovo App Shop, Lenovo Companion, Lenovo Reach, and so on.

This isn’t the first time Lenovo has experienced troubles with its pre-installed software. The company faced a lawsuit early last year after it pre-installed the SuperFish “man-in-the-middle” adware on a number of its consumer-based PCs. SuperFish not only injects suggested ads into search results, but can cause severe security issues. The company admitted to making a mistake and distributed fixes that removed applications and certificates based on SuperFish from purchased Lenovo solutions. Uninstall instructions were also provided here.

We reached out to Lenovo for a comment but have yet to receive a reply.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Siri is about to hear everything you say, but Apple’s privacy approach has me cautiously on board
Apple's new Audio Intelligence features want to hear almost everything you say. A privacy document released alongside them explains why I am mostly okay with that.
Apple Watch Audio Intelligence features

Apple used its September 2026 launch event to enter a feature category it has mostly avoided until now: ambient listening. Siri Recap, Live Rewind, Music Recognition with Shazam, and Sound Recognition all landed on the Apple Watch Series 12 and Apple Watch Ultra 4. All four depend on the watch microphone picking up sound around you far more often than any previous Apple product has.

Siri Recap listens for conversations throughout your day and turns them into short AI summaries you can check later. Live Rewind is smaller in scope but arguably more useful day-to-day. It transcribes the last 15 seconds of whatever was just said with a double-press of the crown. This is perfect for catching a name, a book title, or directions you missed the first time. Music Recognition uses Shazam to identify songs playing nearby without you lifting a finger, much like Now Playing on Google's Pixel devices. Sound Recognition is a useful accessibility feature that listens for sirens, doorbells, and alarms to alert users who have a hearing impairment.

Read more
Can You Turn a Mini PC Into a Local AI Agent?
Furniture, Table, Computer

This post is brought to you in paid partnership with MSI

Not every AI task needs the scale of the cloud. An employee searching company documents, a retail kiosk answering product questions, or a digital sign reacting to customer behavior all need fast responses, but they don't necessarily need to send every prompt to a remote data center. Running those workloads locally reduces latency, keeps sensitive information closer to where it's generated, and can lower the ongoing cost of AI deployments. As a result, many organizations are moving toward hybrid AI architectures that handle routine requests on-device while reserving cloud models for tasks that genuinely need more processing power.

Read more
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more