<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lenovo Laptops Vulnerability Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/lenovo-laptops-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/lenovo-laptops-vulnerability/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Thu, 14 Jul 2022 10:34:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Lenovo issues Security Alert relating to 70 laptop models that are Vulnerable</title>
		<link>https://www.gizmochina.com/2022/07/14/lenovo-issues-security-alert-relating-to-70-laptop-models-that-are-vulnerable/</link>
		
		<dc:creator><![CDATA[Divyansh Mehta]]></dc:creator>
		<pubDate>Thu, 14 Jul 2022 10:34:09 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Lenovo]]></category>
		<category><![CDATA[Lenovo Bugs]]></category>
		<category><![CDATA[Lenovo laptops]]></category>
		<category><![CDATA[Lenovo Laptops Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=470668</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>Lenovo has revealed that more than 70 of its laptop models are vulnerable to a UEFI/BIOS bug that could result in arbitrary code execution in a security alert. Three buffer overflow vulnerabilities were found by researchers at the cybersecurity company ESET. According to ESET&#8217;s tweet, the flaws can be used to execute arbitrary code during [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/07/14/lenovo-issues-security-alert-relating-to-70-laptop-models-that-are-vulnerable/">Lenovo issues Security Alert relating to 70 laptop models that are Vulnerable</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2022/03/lenovo-yoga-9i-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p><a href="http://gizmochina.com/tag/lenovo" target="_blank" rel="noopener">Lenovo</a> has revealed that more than 70 of its laptop models are vulnerable to a UEFI/BIOS bug that could result in arbitrary code execution in a <a href="https://support.lenovo.com/us/en/product_security/LEN-91369" target="_blank" rel="noopener">security alert.</a></p>
<p><a href="https://www.gizmochina.com/wp-content/uploads/2016/11/lenovo-logo.png?x44794"><img loading="lazy" class="aligncenter size-full wp-image-106738" src="https://www.gizmochina.com/wp-content/uploads/2016/11/lenovo-logo.png?x44794" alt="lenovo-logo" width="621" height="443" srcset="https://www.gizmochina.com/wp-content/uploads/2016/11/lenovo-logo.png 621w, https://www.gizmochina.com/wp-content/uploads/2016/11/lenovo-logo-300x214.png 300w" sizes="(max-width: 621px) 100vw, 621px" /></a></p>
<p>Three buffer overflow vulnerabilities were found by researchers at the cybersecurity company ESET.</p>
<p><a href="https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1.png?x44794"><img loading="lazy" class="aligncenter size-large wp-image-470687" src="https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-1024x655.png?x44794" alt="Twitter ESET SS" width="696" height="445" srcset="https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-1024x655.png 1024w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-300x192.png 300w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-768x492.png 768w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-696x446.png 696w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-1068x684.png 1068w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1-656x420.png 656w, https://www.gizmochina.com/wp-content/uploads/2022/07/Screenshot-2-1.png 1256w" sizes="(max-width: 696px) 100vw, 696px" /></a></p>
<p>According to <a href="https://twitter.com/ESETresearch/status/1547166334651334657" target="_blank" rel="noopener">ESET&#8217;s tweet</a>, the flaws can be used to execute arbitrary code during the platform boot process, giving attackers the potential to control the OS execution flow and disable key crucial security mechanisms.</p>
<p>&#8220;Insufficient validation of the DataSize parameter given to the UEFI Runtime Services method GetVariable was the root cause of these vulnerabilities. A particularly constructed NVRAM variable might be created by an attacker, leading to a buffer overflow of the Data buffer in the second GetVariable call,&#8221; it continued.</p>
<p>Retbleed is a new speculative execution exploit affecting devices with Intel and AMD CPUs, and Lenovo has also warned users about it.</p>
<p><a href="https://www.gizmochina.com/wp-content/uploads/2022/04/lenovo-ideapad-flex-5i-gen-7-16-intel-features-3.jpg?x44794"><img loading="lazy" class="aligncenter size-full wp-image-456320" src="https://www.gizmochina.com/wp-content/uploads/2022/04/lenovo-ideapad-flex-5i-gen-7-16-intel-features-3.jpg?x44794" alt="lenovo-ideapad-flex-5i-gen-7-16-intel-features-3" width="577" height="445" srcset="https://www.gizmochina.com/wp-content/uploads/2022/04/lenovo-ideapad-flex-5i-gen-7-16-intel-features-3.jpg 577w, https://www.gizmochina.com/wp-content/uploads/2022/04/lenovo-ideapad-flex-5i-gen-7-16-intel-features-3-300x231.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/04/lenovo-ideapad-flex-5i-gen-7-16-intel-features-3-545x420.jpg 545w" sizes="(max-width: 577px) 100vw, 577px" /></a></p>
<p>A couple of vulnerabilities affecting numerous products that use the XClarity Controller server management engine have also been addressed in an advisory from the company. These bugs could give authorized users the ability to disrupt services or establish unauthorized connections to internal ones.</p>
<p>Firmware flaws are a typical occurrence. Researchers have found vulnerabilities in third-party components used by numerous manufacturers, even though some of them are particular to the products of a single vendor.</p>
<p>For instance, the InsydeH2O UEFI firmware code is utilized by more than 25 vendors, such as HP, Lenovo, Fujitsu, Microsoft, Intel, Dell, Bull, and Siemens, and has recently been shown to include over two dozen vulnerabilities.</p>
<p>It may take some time until the remedies are adopted by manufacturers and reach millions of end users, even though Insyde Software, the company that makes InsydeH2O, patched the vulnerabilities as soon as Binarly contacted them. Customers have just lately been told about the existence of remedies for these problems by the manufacturer of the modular and upgradeable Framework laptops.</p>
<p>If you own a Lenovo laptop, go ahead and check if your device model is listed among the 70 affected models using this <strong><a href="https://support.lenovo.com/us/en/product_security/LEN-91369" target="_blank" rel="noopener">link</a></strong>.</p>
<p>&nbsp;</p>
<p><span style="text-decoration: underline;"><strong>RELATED</strong></span></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/07/14/lenovo-thinkpad-x1-fold-gen-2-refined-design-trackpoint/" target="_blank" rel="noopener">Lenovo teases the ThinkPad X1 Fold Gen 2 with a refined design &amp;amp; a TrackPoint</a></li>
<li><a href="https://www.gizmochina.com/2022/07/13/lenovo-unveils-its-fresh-legion-laptops-lineup-with-12th-gen-intel-processors/" target="_blank" rel="noopener">Lenovo unveils its fresh Legion laptops lineup with 12th Gen Intel processors</a></li>
<li><a href="https://www.gizmochina.com/2022/06/29/lenovo-legion-halo-gaming-phone-spotted-at-geekbench-key-details-emerge/" target="_blank" rel="noopener">Lenovo Legion Halo gaming phone spotted at Geekbench, key details emerge</a></li>
</ul>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/07/14/lenovo-issues-security-alert-relating-to-70-laptop-models-that-are-vulnerable/">Lenovo issues Security Alert relating to 70 laptop models that are Vulnerable</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 22/51 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 6/30 queries in 0.013 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-06-23 05:32:07 by W3 Total Cache
-->