Login Register






The issue regarding searched threads returning 404s has been fixed. My apologies. - NekoElf
Thread Rating:
  • 0 Vote(s) - 0 Average


>100 Lenovo Laptop Models Vulnerable filter_list
Author
Message
>100 Lenovo Laptop Models Vulnerable #1
A list of over 100 laptops made by Lenovo are susceptible to several vulnerabilities found by ESET. Updates were rolled out.

Quote:Security firm ESET said Tuesday that it has found several UEFI vulnerabilities in a wide swathe of over 100 different Lenovo consumer laptop models, which can be patched by updating the notebook’s firmware.

The full list of affected laptops includes the Ideapad-3, the Legion 5 Pro-16ACH6 H, and the Yoga Slim 9-14ITL0. ESET discovered the vulnerability late last year. Lenovo then worked to develop a patch and released it on the manufacturer’s website. ESET didn’t say whether these vulnerabilities were actively being exploited in the wild.

Specifically, the three different vulnerabilities would allow an attacker to modify either the protected boot settings or the firmware itself, a change that would survive the reinstallation of the operating system, ESET said. “UEFI threats can be extremely stealthy and dangerous,” the firm wrote. “They are executed early in the boot process, before transferring control to the operating system, which means that they can bypass almost all security measures and mitigations higher in the stack that could prevent their OS payloads from being executed.”

A third vulnerability in the SMI Handler code would allow an attacker with local access and elevated privileges to execute arbitrary code, giving them control of the machine.

Read More: https://www.pcworld.com/article/633410/u...-risk.html
[Image: fSEZXPs.png]

Reply

RE: >100 Lenovo Laptop Models Vulnerable #2
I hate when websites have to use redirect links to profit off of these things. EVERY link in that page contains an affiliate link so that PCWorld gets a commission either by click-through or direct means. It should be criminal. Here are the links on that page without any bullshit:

https://support.lenovo.com/pa/en/product.../len-73440
https://www.welivesecurity.com/2022/04/1...r-laptops/
https://pcsupport.lenovo.com/us/en/
https://support.lenovo.com/us/en/product.../LEN-73440
https://support.lenovo.com/us/en/product...20Notebook
https://github.com/eset/vulnerability-disclosures/
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: >100 Lenovo Laptop Models Vulnerable #3
(04-19-2022, 11:08 PM)vittring Wrote: I hate when websites have to use redirect links to profit off of these things. EVERY link in that page contains an affiliate link so that PCWorld gets a commission either by click-through or direct means. It should be criminal. Here are the links on that page without any bullshit:

https://support.lenovo.com/pa/en/product.../len-73440
https://www.welivesecurity.com/2022/04/1...r-laptops/
https://pcsupport.lenovo.com/us/en/
https://support.lenovo.com/us/en/product.../LEN-73440
https://support.lenovo.com/us/en/product...20Notebook
https://github.com/eset/vulnerability-disclosures/

That's shitty. I've gone ahead and edited the post to use direct links.
[Image: fSEZXPs.png]

Reply

RE: >100 Lenovo Laptop Models Vulnerable #4
All good. Considering that a lot of websites are barely staying afloat right now, I understand the reasoning. But you don't just enforce affiliate links across your entire website. That doesn't fly.
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: >100 Lenovo Laptop Models Vulnerable #5
(04-19-2022, 11:08 PM)vittring Wrote: I hate when websites have to use redirect links to profit off of these things. EVERY link in that page contains an affiliate link so that PCWorld gets a commission either by click-through or direct means. It should be criminal.
I couldn't agree more.

It's pathetic how companies on that scale, stoop so low to use redirection links.

(04-19-2022, 11:08 PM)vittring Wrote: Here are the links on that page without any bullshit:

https://support.lenovo.com/pa/en/product.../len-73440
https://www.welivesecurity.com/2022/04/1...r-laptops/
https://pcsupport.lenovo.com/us/en/
https://support.lenovo.com/us/en/product.../LEN-73440
https://support.lenovo.com/us/en/product...20Notebook
https://github.com/eset/vulnerability-disclosures/
Good work.
[Image: AD83g1A.png]

Reply







Users browsing this thread: 4 Guest(s)