Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Lenovo ThinkPad zero-day bypasses Windows security
iTnews (AUS) ^ | Jul 4 2016 6:41AM (AUS) | Juha Saarinen

Posted on 07/03/2016 4:15:43 PM PDT by Utilizer

A researcher has discovered a new low-level zero-day exploit that overrides the protection for the firmware code in Lenovo ThinkPads and other laptops, bypassing hardware and Windows security features.

Last week, Dmytro Oleksiuk, also known as cr4sh, released the code for his ThnkPwn proof of concept on Github, showing how it can be used to exploit a flaw in the unified extensible firmware interface (UEFI) driver for privilege escalation.

This lets attackers remove the write protection for system flash memory, and allows them to run arbitrary code with full access to the entire victim system.

Lenovo had not received advance notification of the vulnerability, making the exploit a zero-day with no mitigation available.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: lenovo; lenovothinkpad; malware; microsoft; thinkpad; virusware; windows10; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first 1-2021-33 next last
More 'doze security woes, this time from the manufacturing end for this troubled OS.
1 posted on 07/03/2016 4:15:43 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

Hardware bump!


2 posted on 07/03/2016 4:16:38 PM PDT by Utilizer
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Lenovo has been infamous for years for its security issues...


3 posted on 07/03/2016 4:18:57 PM PDT by 867V309 (It's over. It's over now.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: 867V309
Lenovo has been infamous for years for its security issues

The ChiComs used to ship them with spyware pre-installed.

Lenovo Caught (3rd Time) Pre-Installing Spyware on its Laptops
http://thehackernews.com/2015/09/lenovo-laptop-virus.html

Yet another pre-installed spyware app discovered on Lenovo ...
http://boingboing.net/2015/09/22/yet-another-pre-installed-spyw.html

4 posted on 07/03/2016 4:22:24 PM PDT by PAR35
[ Post Reply | Private Reply | To 3 | View Replies]

To: 867V309

And now yet another one.


5 posted on 07/03/2016 4:35:43 PM PDT by Utilizer
[ Post Reply | Private Reply | To 3 | View Replies]

To: PAR35

Perhaps the OpenBIOS coders can help out here...


6 posted on 07/03/2016 4:36:24 PM PDT by Utilizer
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

This looks pre-windows. Conceivably you could have a machine with no OS of any flavor and compromise the firmware. Since you’re addressing the firmware the exploit would remain independent of OS - or even a HDD bring present.


7 posted on 07/03/2016 4:41:48 PM PDT by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 867V309

Glad I don’t use any in the office.


8 posted on 07/03/2016 4:56:48 PM PDT by wally_bert (I didn't get where I am today by selling ice cream tasting of bookends, pumice stone & West Germany)
[ Post Reply | Private Reply | To 3 | View Replies]

To: rockrr

I think you mean: pre- windows loading.

I think now that the flaw has been discovered that the OpenBIOS people can write in a script to bypass it and render it ineffective.

Of course, couple this with the discovery quite recently that there are some CPUs shipping with an embedded alternate CPU that can be accessed under certain circumstances and a quite troublesome trend appears to be emerging...


9 posted on 07/03/2016 5:29:05 PM PDT by Utilizer
[ Post Reply | Private Reply | To 7 | View Replies]

To: PAR35

3 years ago, NASA awarded the ACES contract, the contract that supplies all computers to NASA, to HP. Guess what HP started putting on folks desks?

Lenovo computers.

I personally heard an IT guy tell me of them setting up new computers for configuration.... and the new computers, OUT OF THE BOX, established a connection to China and started uploading.

Security personnel caught the breach in about 5 minutes and came running into the room pulling network cables.


10 posted on 07/03/2016 5:44:10 PM PDT by Bryan24 (When in doubt, move to the right..........)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bryan24

.
“Nice working with you Dave!”
.


11 posted on 07/03/2016 5:52:29 PM PDT by editor-surveyor (Freepers: Not as smart as I'd hoped they'd be)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Bryan24

HP = Has Problems.

Yet another reason to avoid HP and Lenovo.


12 posted on 07/03/2016 5:55:56 PM PDT by wally_bert (I didn't get where I am today by selling ice cream tasting of bookends, pumice stone & West Germany)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
Lenovo ZERO-DAY hardware vulnerability ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Utilizer for the ping!

Note this could affect -any- OS on the Lenovo hardware; but of course most Lenovo's run Windows...

13 posted on 07/03/2016 5:57:50 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: wally_bert

I dunno... with very few exceptions, pretty much every machine I work with on a constant basis is an HP machine.

Well, and some Compaqs as well, but since HP bought out Compaq they are now the same company so I suppose the distinction matters only to the purists and old-timers still mucking about out there. :)


14 posted on 07/03/2016 6:05:14 PM PDT by Utilizer
[ Post Reply | Private Reply | To 12 | View Replies]

To: Utilizer

The very first line specifically states that the fault is in the firmware for the laptop. I always love when you post a Windows article, Utilizer. You’re usually good for a chuckle.


15 posted on 07/03/2016 6:06:07 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
> couple this with the discovery quite recently that there are some CPUs shipping with an embedded alternate CPU

It was determined that the second CPU was the "Management Engine" in the motherboard chipset (NOT the main x86 CPU), that it has been there for a LONG time, and was known about but largely ignored except for special cases like enterprise deployments.

These fancy chipsets have to have their own embedded CPUs to do command, configuration, and control on the motherboard, communicating with the main CPU when required. How the heck else could all those features be programmed?

So I'm not sure that ranks as a "recent discovery". More like "increased awareness". Area 51 it ain't. :-)

16 posted on 07/03/2016 6:06:20 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 9 | View Replies]

To: wally_bert

Hps always gave us problems because of their proprietary bios and startup crap.


17 posted on 07/03/2016 6:17:09 PM PDT by Secret Agent Man (Gone Galt; Not averse to Going Bronson.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: rarestia

Glad to help your amusement along mate!

Cheers! :-b


18 posted on 07/03/2016 6:19:40 PM PDT by Utilizer
[ Post Reply | Private Reply | To 15 | View Replies]

To: dayglored

In the same manner that the OS NSA Backdoor Code was there all along and pretty much ignored by everyone who came across it.

Until some people started asking questions...

The second CPU is claimed to be nonoperational for the vast majority of the machines out there.

And you trust the word of company employees who derive a large part of their corporate earnings (and thus their salary) on the claims of their official bosses?

I think after past history is taken into account we should all err on the side of caution and act like the machine might well be compromised.

Rather like you ALWAYS assume the WebCam is ACTIVE... and remember to take precautionary measures at all times.


19 posted on 07/03/2016 6:25:50 PM PDT by Utilizer
[ Post Reply | Private Reply | To 16 | View Replies]

To: Utilizer

This was put in by the Chinese as a backdoor.

Lenovo is Chinese owned and they want access to our secrets.


20 posted on 07/03/2016 6:49:22 PM PDT by ConservativeMind ("Humane" = "Don't pen up pets or eat meat, but allow infanticide, abortion, and euthanasia.")
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-33 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson