https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Tech Services Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • MSP 501 Information Center
    • 2021 MSP 501 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2021 MSP 501
    • Circle of Excellence
    • DE&I 101
    • Top Gun 51
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Vulnerability

ESET: Millions Using Lenovo Laptops Potentially Vulnerable to Malware Attacks

  • Written by Edward Gately
  • April 20, 2022
The vulnerabilities could be in laptops used by businesses.

More than 100 models of Lenovo laptops used by millions globally contain vulnerabilities that could allow attackers to deploy and successfully execute unified extensible firmware interface (UEFI) malware.

ESET discovered the vulnerabilities and reported them to Lenovo last October. Lenovo sent us the following statement:

“Lenovo thanks ESET for bringing to our attention an issue in drivers used in the manufacturing of some consumer notebooks. The drivers have been fixed, and customers who update as described in the Lenovo advisory are protected. Lenovo welcomes collaboration with BIOS (firmware that runs while a computer boots up) researchers as we increase our investments in BIOS security to ensure our products continue to meet or exceed industry standards.”

ESET Discovers 3 Vulnerabilities

Tony Anscombe is chief security evangelist at ESET.

ESET's Tony Anscombe

ESET’s Tony Anscombe

“If the vulnerability is exploited, there is potential that the bad actor could deploy threats such as LoJax or ESPecter,” he said. “Threats such as these allow the attacker to insert malware into the boot process of the operating system, thus circumventing many of the security measures that would be in place during a normal boot process.”

Lenovo markets the vulnerable devices to consumers, Anscombe said.

“However, small businesses or organizations that have less stringent rules on device types may be using consumer devices in a business environment,” he said. “All Lenovo users should check if their device is on the list.”

The first two of these vulnerabilities affect UEFI firmware drivers originally meant to be used only during the manufacturing process of Lenovo consumer notebooks. Attackers can disable SPI flash protections or the UEFI Secure Boot feature from a privileged user-mode process during OS runtime.

The third vulnerability allows arbitrary read/write from/into the special memory range (SMRAM). That can lead to the execution of malicious code with system management mode (SMM) privileges and potentially lead to the deployment of an SPI flash implant.

Extremely Stealthy and Dangerous

Martin Smolár is the ESET researcher who discovered the vulnerabilities in Lenovo laptops.

ESET's Martin Smolár

ESET’s Martin Smolár

“UEFI threats can be extremely stealthy and dangerous,” he said. “Our discovery demonstrates that in some cases, deployment of the UEFI threats might not be as difficult as expected.”

Threats can bypass almost all security measures and mitigations higher in the stack, according to ESET. It also appears that UEFI vulnerabilities are growing, and that bad actors are aware of this.

Ray Steen is chief strategy officer of MainSpring, a Washington, D.C., area managed IT service provider. He said Lenovo isn’t the first vendor to include “out-of-the-box” security vulnerabilities in its products. This leaves “countless workstations” susceptible to firmware-level attacks.

“In recent years, software and hardware supply chains have been sources of escalating risk, reminding us that cybersecurity cannot be an afterthought in the modern business environment,” he said.

Now more than ever, organizations need support from C-level cybersecurity professionals like CIOs and virtual CIOs, Steen said. They can evaluate vendors for security practices, implement patches and more.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Best Practices Channel Research Desktop Mobility & Wireless MSSP Insider Security

Most Recent


  • North America
    Kaspersky Channel Vet Joins Cyware to Lead its North America Channel
    Cyware partners can expect improvements in the company's partner program.
  • customer experience - cx
    Build Customers for Life with CX and Lifecycle Selling
    Companies that offer a good customer experience are more likely to see their revenue grow faster than those that don't make CX a top priority.
  • Cybersecurity challenges
    Unprecedented Times Impacting Cybersecurity Channel Partners
    Channel leaders have to adapt to changes in market routes.
  • Best practices
    AWS Security Best Practices: A Baker's Dozen for Success in the Cloud
    From implementing the principle of least privilege to cloud workload protection, following these tips makes for a more secure cloud infrastructure.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Broken Blockchain
    Alert: North Korea Hackers Targeting Blockchain, Crypto Companies
  • cybersecurity strategy
    The Gately Report: CP Expo Edition with Trellix's Kristi Houssiere, Cybersecurity Peer Group, More
  • Full wallet
    The Gately Report: Delinea Focused on Expanding Partners' 'Wallet Share,' Zoom Shells Out for Bug Bounties
  • Cloud security
    Google Cloud Takes on Rivals AWS, Azure in Broader Pursuit of MSSPs

Upcoming Events

View all

Channel Partners Europe

June 14, 2022 - June 15, 2022

MSP Summit

September 13, 2022 - September 16, 2022

Galleries

View all

Unprecedented Times Impacting Cybersecurity Channel Partners

May 16, 2022

8 Channel People Making Waves This Week at Avant, Cisco, Databricks, More

May 13, 2022

Talent Shortage Ripple Effects Continue to Create Headaches for Partners

May 13, 2022

Industry Perspectives

View all

Build Customers for Life with CX and Lifecycle Selling

May 16, 2022

Voice Analytics Are a Must-Have as Companies Evolve COVID-Rushed Tech

May 12, 2022

Top 5 Trends and Challenges Channel Partners Are Facing in 2022

May 9, 2022

Webinars

View all

Simplifying SaaS Security for MSPs

April 27, 2022

How to Supercharge The Network to Support Your IT Superhero Moves

May 3, 2022

The 2022 MSP Challenge: Scale Service Delivery Despite the Talent Gap

April 21, 2022

White Papers

View all

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

The AT&T Cybersecurity Incident Response Toolkit

April 4, 2022

Channel Futures TV

View all

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

Vonage Addresses Potential Partner Opportunity via Acquisition by Ericsson

May 5, 2022

Lumen Technologies ‘Built for Growth and Scale’

May 4, 2022

Twitter

ChannelFutures

.@1111systems has snagged certain key managed service and cloud infrastructure assets through two key acquisitions.… twitter.com/i/web/status/1…

May 16, 2022
ChannelFutures

.@kaspersky vet to lead @CywareCo's North America channel. #cybersecurity dlvr.it/SQV5S3 https://t.co/2n9CZ4H6Ke

May 16, 2022
ChannelFutures

How to build and provide a great customer experience. #CX #ChannelPartners @IngramMicroInc dlvr.it/SQTrfh https://t.co/RsAA2Lliek

May 16, 2022
ChannelFutures

[email protected] global channel chief Rodney Clark made the surprise announcement he is leaving his position just one ye… twitter.com/i/web/status/1…

May 16, 2022
ChannelFutures

.@SAP touts growth of Rise with SAP at #SAPSapphireOrlando dlvr.it/SQTCs5 https://t.co/J2LrQrYlNQ

May 16, 2022
ChannelFutures

#CPExpo #cybersecurity roundtable discusses unprecedented times for channel chiefs, partners. @Sophos, @Fortinet,… twitter.com/i/web/status/1…

May 16, 2022
ChannelFutures

Being #cybersecurity proactive about the threat landscape makes a better #cloudcomputing strategy, says… twitter.com/i/web/status/1…

May 16, 2022
ChannelFutures

As many MSPs deal with continuing hiring shortages, there is a growing need to find and retain the right talent.… twitter.com/i/web/status/1…

May 13, 2022

MSSP Insider

Business advice for MSSPs and news from the broader security channel.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X