SafeUM
Home Blog Services Download Help About Recharge
EN
RU

Axarhöfði 14, 110 Reykjavik, Iceland

Iceland - 2015
SafeUM
Blog
Services
Download
Help
About
Recharge
Menu
EN
Lang
EN
RU
Archive
TOP Security!
29 Jun 2016

Lenovo patches two high severity flaws in PC support tool

Lenovo has fixed two high-severity vulnerabilities in the Lenovo Solution Center support tool that is preinstalled on many laptop and desktop PCs. The flaws could allow attackers to take over computers and terminate antivirus processes.

Lenovo Solution Center (LSC) allows users to check their system's virus and firewall status, update their Lenovo software, perform backups, check battery health, get registration and warranty information and run hardware tests. 

The two new vulnerabilities, tracked as CVE-2016-5249 and CVE-2016-5248 in the Common Vulnerabilities and Exposures database, were found by security researchers from Trustwave. They affect LSC versions 3.3.002 and earlier. The CVE-2016-5249 vulnerability allows an attacker who already has control of a limited account on a PC to execute malicious code via the privileged LocalSystem account.

Privilege escalation flaws like this one cannot be used by themselves to compromise computers, but are often used in exploit chains. Due to security improvements in modern operating systems, remote code execution flaws don't always provide attackers with full control over affected systems and need to be combined with privilege escalation vulnerabilities.

Because of the functionality in the LSC.Services.SystemService component, any local user can open a communication pipe to the service and force it to execute arbitrary .NET code. Because this LSC service runs under the LocalSystem account, the rogue code would also be executed with LocalSystem privileges.

The second vulnerability, CVE-2016-5248, allows any local user to send a command to LSC.Services.SystemService in order to kill any other process on the system, privileged or not. The target process could, for example, belong to an antivirus program or another security product.

Lenovo advises users to upgrade to LSC version 3.3.003. This can be done from the application itself by agreeing to automatic update prompt, from the separate Lenovo System Update utility or by downloading the latest version of LSC manually.

This is not the first time that serious flaws were found in LSC. However, Lenovo seems to be responding to such vulnerabilities in a timely manner by releasing patches and publishing security advisories. In a recent security analysis of the update tools preloaded on computers PC manufacturers, LSC was found to have one of the most secure implementations.

Tags:
Lenovo information leaks
Source:
Network World
866
Other NEWS
25 Apr 2018 safeum news imgage Amazon has a top-secret plan to build home robots
24 Apr 2018 safeum news imgage Advanced hackers infect X-Ray machines in healthcare espionage
23 Apr 2018 safeum news imgage 'Trustjacking' could expose iPhones to attack
20 Apr 2018 safeum news imgage Google boots fake Ad blockers from Chrome web store
20 Apr 2018 safeum news imgage Data firm leaks 48 million user profiles it scraped from Facebook, LinkedIn, others
19 Apr 2018 safeum news imgage Critical unpatched RCE flaw disclosed in LG network storage devices
18 Apr 2018 safeum news imgage Apple is planning to launch a news subscription service
18 Apr 2018 safeum news imgage A big Spanish bank’s customers can now use it to transfer money
17 Apr 2018 safeum news imgage How Android phones hide missed security updates from you
16 Apr 2018 safeum news imgage Google is testing self-destructing emails in new Gmail
16 Apr 2018 safeum news imgage In a leaked memo, Apple warns employees to stop leaking information
13 Apr 2018 safeum news imgage WannaCry ransomware sinkhole data now available to organizations
13 Apr 2018 safeum news imgage Apple must pay $502.6 million to VirnetX, federal jury rules
12 Apr 2018 safeum news imgage Vevo’s YouTube account hack hits popular music videos, causes biggest video ever to disappear
11 Apr 2018 safeum news imgage Homeland security to compile database of journalists, bloggers
All news
SafeUM
Confidential Our technologies Company
Follow us
Download
SafeUM © Safe Universal Messenger

Axarhöfði 14,
110 Reykjavik, Iceland

Iceland - 2015