Security News Lenovo tells users to uninstall vulnerable Accelerator app

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
In the wake of Duo Security’s report on the critical vulnerabilities sported by Original Equipment Manufacturer (OEM) updaters loaded on popular laptop and desktop computers, Lenovo has advised users to uninstall its Accelerator Application.


OEM-vendor-issues.jpg




“The vulnerability (CVE-2016-3944) resides within the update mechanism where a Lenovo server is queried to identify if application updates are available,” the company explained.

The flaw can be exploited by an attacker with local network access to perform remote code execution and take over control of the machine.

The Accelerator Application is apparently used to speed up the launch of the company’s applications, and is present on some Lenovo consumer notebook and desktop systems preloaded with Windows 10, but not on ThinkPad or ThinkStation devices.

Full Article. Lenovo tells users to uninstall vulnerable Accelerator app - Help Net Security
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Honestly those Accelerator or other necessary bundled programs pose more risk than benefits. Lenovo should go back to their homework on providing partnership to other products.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top