ESET finds UEFI vulnerabilities in 25 Lenovo laptop models – the company has already closed two out of three issues

ESET has discovered UEFI vulnerabilities in 25 Lenovo laptop models - the company has already closed two out of three issues

More than two dozen Lenovo laptop models are vulnerable to a hack that disables UEFI Secure Boot and then runs unsigned code or blocks the device from booting.

Researchers at ESET uncovered the vulnerability and announced it on November 9, one day after the laptop manufacturer released security updates for the 25 device models listed here . Owners of laptops from the list are strongly advised to update the UEFI of their devices. At the same time, Lenovo fixed only two of the three vulnerabilities.

ESET stated that the vulnerabilities designated as CVE-2022-3430, CVE-2022-3431 and CVE-2022-3432 allow you to disable UEFI Secure Boot or rollback Secure Boot databases to factory state directly from the operating system. Disabling or restoring databases to their defaults allows an attacker to remove restrictions that are normally in place.

The discovered vulnerabilities can be exploited by modifying variables in NVRAM, which stores various boot parameters. The vulnerabilities are the result of Lenovo erroneously shipping laptops with drivers intended for production use only. A more detailed description of each of the vulnerabilities:

Well

Full Stack distribution

Learn for a free schedule to become a universal teacher of knowledge of Back-end and Front-end. Earn $1300 per month

REGISTER!

Full Stack distribution
  • CVE-2022-3430: A potential vulnerability in the WMI configuration driver on some Lenovo consumer laptops could allow an elevated attacker to change Secure Boot settings by modifying the NVRAM variable.
  • CVE-2022-3431: A potential vulnerability in a driver used during manufacturing on some Lenovo consumer laptops that was mistakenly not deactivated could allow an elevated attacker to change the Secure Boot setting by modifying the NVRAM variable.
  • CVE-2022-3432: A potential vulnerability in a driver used in the manufacturing process of the Ideapad Y700-14ISK laptop that was mistakenly not deactivated could allow an elevated attacker to change the Secure Boot setting by modifying the NVRAM variable.

Lenovo fixed only the first two vulnerabilities. CVE-2022-3432 will not be fixed as the company has not supported the Ideapad Y700-14ISK laptop model for several years.

Source: Ars Technica

Related Posts

UK to regulate cryptocurrency memes: illegal advertising

Britain’s financial services regulator has issued guidance to financial services companies and social media influencers who create memes about cryptocurrencies and other investments to regulate them amid…

unofficial renders of the Google Pixel 9 and information about the Pixel 9 Pro XL

The whistleblower @OnLeaks and the site 91mobiles presented the renders of the Google Pixel 9 phone. Four images and a 360° video show a black smartphone with…

Embracer to sell Gearbox (Borderlands) to Take-Two (Rockstar and 2K) for $460 million

Embracer continues to sell off assets – the Swedish gaming holding has just confirmed the sale of The Gearbox Entertainment studio to Take-Two Interactive. The sum is…

photo of the new Xbox X console

The eXputer site managed to get a photo of a new modification of the Microsoft Xbox game console. The source reports that it is a white Xbox…

Israel Deploys Massive Facial Recognition Program in Gaza, – The New York Times

The Technology section is powered by Favbet Tech The images are matched against a database of Palestinians with ties to Hamas. According to The New York Times,…

Twitch has banned chest and buttock broadcasts of gameplay

Twitch has updated its community rules and banned the focus of streams on breasts and buttocks. According to the update, starting March 29, “content that focuses on…

Leave a Reply

Your email address will not be published. Required fields are marked *