Security5.07.2016

Critical Lenovo security vulnerability

A critical Lenovo security flaw has been discovered which could let attackers bypass Windows’ basic security protocols.

Lenovo’s said it is aware of the BIOS vulnerability located in the System Management Mode (SMM) code that impacts certain Lenovo PCs.

The disclosure follows security researcher Dymtro “Cr4sh” Oleksiuk revealing the BIOS vulnerability.

Lenovo said it made several unsuccessful attempts to collaborate with the researcher before his announcement.

Lenovo said the vulnerable SMM code was provided to it by at least one of its Independent BIOS Vendors (IBVs).

“The package of code with the SMM vulnerability was developed on top of a common code base provided to the IBV by Intel,” said Lenovo.

“Because Lenovo did not develop the code and is determining the identity of the author, it does not know its intended purpose.”

Lenovo said it is working on identifying additional instances of the vulnerability’s presence in the BIOS provided to Lenovo by other IBVs.

More on Lenovo

New Motorola and Lenovo smartphones coming to South Africa

Lenovo launches Phab 2 Pro – the first Google Tango smartphone

Show comments

Latest news

More news

Trending news

Poll

Which operating system do you have installed on your personal computer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter