Lenovo patches two high severity flaws in PC support tool

The flaws could allow attackers to execute malicious code with system privileges and to kill other processes

Lenovo has fixed two high-severity vulnerabilities in the Lenovo Solution Center support tool that is preinstalled on many laptop and desktop PCs. The flaws could allow attackers to take over computers and terminate antivirus processes.

Lenovo Solution Center (LSC) allows users to check their system's virus and firewall status, update their Lenovo software, perform backups, check battery health, get registration and warranty information and run hardware tests.

The two new vulnerabilities, tracked as CVE-2016-5249 and CVE-2016-5248 in the Common Vulnerabilities and Exposures database, were found by security researchers from Trustwave. They affect LSC versions 3.3.002 and earlier.

The CVE-2016-5249 vulnerability allows an attacker who already has control of a limited account on a PC to execute malicious code via the privileged LocalSystem account.

Privilege escalation flaws like this one cannot be used by themselves to compromise computers, but are often used in exploit chains. Due to security improvements in modern operating systems, remote code execution flaws don't always provide attackers with full control over affected systems and need to be combined with privilege escalation vulnerabilities.

Because of the functionality in the LSC.Services.SystemService component, any local user can open a communication pipe to the service and force it to execute arbitrary .NET code. Because this LSC service runs under the LocalSystem account, the rogue code would also be executed with LocalSystem privileges.

The second vulnerability, CVE-2016-5248, allows any local user to send a command to LSC.Services.SystemService in order to kill any other process on the system, privileged or not. The target process could, for example, belong to an antivirus program or another security product.

Lenovo advises users to upgrade to LSC version 3.3.003. This can be done from the application itself by agreeing to automatic update prompt, from the separate Lenovo System Update utility or by downloading the latest version of LSC manually.

This is not the first time that serious flaws were found in LSC. However, Lenovo seems to be responding to such vulnerabilities in a timely manner by releasing patches and publishing security advisories. In a recent security analysis of the update tools preloaded on computers PC manufacturers, LSC was found to have one of the most secure implementations.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?