Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324
Clear as mud. Lenovo has previously sacrificed user security and privacy for money (superfish), so it does not surprise me that they have done it again, and these kinds of weasel words aren't going to get me to buy another Lenovo product again. Here's an idea: How about not putting backdoors in our products? How about making it easier for consumers to replace software on systems they own?
ThinkPwn: System Management Mode arbitrary code execution
21–30 of 154 posts
Re: ThinkPwn: System Management Mode arbitrary code execution
#22Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324
Maybe author did not want to deal with Lenovo. > Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose.
Although based on the author's original blog post and title for the GitHub repo, it seems that he originally thought it was Lenovo specific...
Re: ThinkPwn: System Management Mode arbitrary code execution
#23T450S user here. What exactly does this mean for me? I get it's a security issue, but that's about all I understood...
What shipping and receiving? Somewhere between where you will receive the package -- be it your home, PO Box, postal office, etc -- and the originating storage facility (ie: warehouse), there is a long list of hands exchanging your product. One of these hands would be an NSA agent's hands.
https://en.wikipedia.org/wiki/Interdiction
Who is targeted? In all likelihood, businesses, but I'm sure individuals are targeted as well.
The attack requires physical access to the hardware.
And just to be clear -- it's not just Lenovo products. The net seems to have been cast much wider and other devices seem to be affected (HP laptops, desktop motherboards).
Re: ThinkPwn: System Management Mode arbitrary code execution
#24> Vulnerable code of SystemSmmRuntimeRt UEFI driver was copy-pasted by Lenovo from Intel reference code for 8-series chipsets. > Alex James found vulnerable code on motherboards from GIGABYTE (Z68-UD3H, Z77X-UD5H, Z87MX-D3H, Z97-D3H and many others): This is beyond the scope of just Lenovo machines.
Re: ThinkPwn: System Management Mode arbitrary code execution
#25It's a little sad to be excited about a vulnerability because it might provide an opportunity for a consumer open up the products they rightfully purchased.
Re: ThinkPwn: System Management Mode arbitrary code execution
#26Earlier quoted context omitted.
I think this exploit requires local administrative access. If an attacker already has this, you're pretty screwed to begin with. In other words, while this could definitely make an attack more damaging and harder to remove, it doesn't seem like a reason to stop using a computer that has decent software and physical security.
This exploit just requires physical, not administrative, access to the machine. You build an EFI "app", put it on a flash drive, and execute it from the UEFI shell.
If you can get someone to run a USB that'll boot you open the user up to a bazillion exploits already and already own the machine.
Re: ThinkPwn: System Management Mode arbitrary code execution
#27Interesting bit form Lenovo's security advisory on the matter[0]: > Shortly after the researcher stated over social media that he would disclose a BIOS-level vulnerability in Lenovo products, Lenovo PSIRT made several unsuccessful attempts to collaborate with the researcher in advance of his publication of this information. [0] https://support.lenovo.com/us/en/solutions/LEN-8324
Maybe author did not want to deal with Lenovo. > Lenovo did not develop the vulnerable SMM code and is still in the process of determining the identity of the original author, it does not know its originally intended purpose.
Re: ThinkPwn: System Management Mode arbitrary code execution
#28Re: ThinkPwn: System Management Mode arbitrary code execution
#29Really hope Lenovo respond soon. Feel like I should leave my ThinkPads hibernated for now.
Re: ThinkPwn: System Management Mode arbitrary code execution
#30What are we up to now? Three preloaded spyware scandals, possible remote execution via the Intel stack and now this vulnerability. That's just what we know about, who knows what else exists. I don't think I can buy another one, which is sad as I think it was a timeless and great design.
I plan on using my quad core T520 for probably another 5+ years. All of their laptops after the T520 series have the full size keyboard with numberpad which off-sets the center of the keyboard, so now your typing is mostly happing on the left side of the keyboard and that causes wrist strain. Having a numberpad is really lame on a laptop. I won't buy one and I know of no one else that likes the numberpad either.. sad…