Slashdot Mirror


Lenovo Warns Users To Upgrade Pre-Installed Tool With Severe Security Holes

Long-time Slashdot reader itwbennett writes: Lenovo is advising users to upgrade to version 3.3.003 of Lenovo Solution Center (LSC), which includes fixes for two high-severity vulnerabilities in the tool. [The tool] allows users to check their system's virus and firewall status, update their Lenovo software, perform backups, check battery health, get registration and warranty information and run hardware tests.

The CVE-2016-5249 vulnerability allows an attacker who already has control of a limited account on a PC to execute malicious code via the privileged LocalSystem account. And the CVE-2016-5248 vulnerability allows any local user to send a command to LSC.Services.SystemService in order to kill any other process on the system, privileged or not.

7 of 43 comments (clear)

  1. Here it is by Anonymous Coward · · Score: 3, Insightful

    allows users to check their system's virus and firewall status, update their Lenovo software, perform backups, check battery health, get registration and warranty information and run hardware tests.

    So, completely pointless bullshit that has no legitimate reason to exist.

    1. Re:Here it is by PsychoSlashDot · · Score: 3, Insightful

      allows users to check their system's virus and firewall status, update their Lenovo software, perform backups, check battery health, get registration and warranty information and run hardware tests.

      So, completely pointless bullshit that has no legitimate reason to exist.

      Not exactly. While the antivirus status is redundant, the rest isn't. Being notified that your warranty is about to expire is a good thing. Being notified that you haven't done a backup recently is a good thing. Being informed that the battery in your laptop is degraded is a good thing. Having something run scheduled tests of basic peripherals is better than not doing so, even though typically you'll know when there's a problem because your system stops working.

      While IT-fluent people are probably doing this sort of thing on their own, the vast majority of machines are either lightly managed or not managed at all.

      It's easy to mock yet another software package that is flawed. But the idea that the software is unjustified and without use is false, in most users' cases.

      --
      "Oh no... he found the .sig setting."
  2. Re:Third time by rudy_wayne · · Score: 2

    Since it's coming from Lenovo they aren't making any money by installing it, so I really don't understand the motivation for putting useless bullshit on their computers.

  3. No trust since SuperFish ? by martiniturbide · · Score: 2

    It seems dumb to post every little security update to Lenovo software. It is like posting the Windows security fixes each week. It will be better to post this kind of news if a chaos starts because of this. Is this because we lost the trust with SuperFish? or it is because it is a Chinese company?

  4. I've got a permanent fix by zuckie13 · · Score: 2

    Uninstall all software like this put on there by the hardware vendor (goes for any vendor). My firewall software can tell me if that's on. My antivirus can tell me if that's on. I can perform my own backups thank you. There ya go, fixed forever.

  5. here is the Lenovo Solution Center download by Aryeh+Goretsky · · Score: 4, Informative

    Hello,

    Since neither the original poster or the article provided it, here's a link to the page where the latest version of the Lenovo Solution Center can be downloaded from:

    https://support.lenovo.com/us/...

    Note that the downloads are listed at the bottom of the page.

    Regards,

    Aryeh Goretsky

    --
    Dexter is a good dog.
  6. 1st step by Archfeld · · Score: 2

    Lets face it, if you buy a pre-installed system these days your 1st step should always be format and install a 'clean' version of an OS, whatever flavor you choose.

    --
    errr....umm...*whooosh* *whoosh* Is this thing on ?