Lenovo issues firmware updates after UEFI vulnerabilities disclosed
- Reference: 1657815314
- News link: https://www.theregister.co.uk/2022/07/14/lenovo_uefi_vuln/
- Source link:
The PC maker has now fixed the trio of bugs, which were flagged up by ESET this week. More than 70 models were impacted by this latest issue, including a number of ThinkBook devices. The vulnerabilities reported were buffer overflows in the UEFI firmware.
"The vulnerabilities," [1]explained the ESET Research team, "can be exploited to achieve arbitrary code execution in the early phases of the platform boot, possibly allowing the attackers to hijack the OS execution flow and disable some important security features."
[2]
"It's a typical UEFI 'double GetVariable' vulnerability," the team added, before giving a hat tip to efiXplorer.
[3]
[4]
Lenovo [5]has published an advisory on the matter this week: the CVE identifiers are CVE-2022-1890, CVE-2022-1891, CVE-2022-1892. All are related to buffer overflows and carry the risk that an attacker with local privileges will be able to execute arbitrary code. Their severity was rated as medium.
As for mitigation, updating the firmware is pretty much all customers can do, although [6]not all products are affected by all three vulnerabilities . All of the products, however, do seem to be hit by CVE-2022-1892, a buffer overflow in the SystemBootManagerDxe driver.
[7]Choosing a non-Windows OS on Lenovo Secured-core PCs is trickier than it should be
[8]Will Lenovo ever think beyond hardware?
[9]Lenovo reveals small but mighty desktop workstation
[10]Lenovo, Barcelona Supercomputing Center sign joint research deal
The disclosure follows another three vulnerabilities [11]patched in April , also concerned with UEFI on Lenovo kit. UEFI, or Unified Extensible Firmware Interface, is the glue connecting a device's firmware with the operating system on top. A vulnerability there could potentially be exploited before a device gets a chance to boot its operating system and fire up malware protections, allowing the computer to become deeply infected and compromised.
ESET research noted that the flaws were a result of "insufficient validation of DataSize parameter passed to the UEFI Runtime Services function GetVariable."
These vulnerabilities were caused by insufficient validation of DataSize parameter passed to the UEFI Runtime Services function GetVariable. An attacker could create a specially crafted NVRAM variable, causing buffer overflow of the Data buffer in the second GetVariable call. 3/6 [12]pic.twitter.com/HC5ow6KTN0 — ESET research (@ESETresearch) [13]July 13, 2022
ThinkPad hardware is not affected, probably to the relief of harassed enterprise administrators around the world. Other Lenovo device users should check the list and perform a firmware update if needed.
The Register asked ESET for more detail on how these vulnerabilities could be exploited, and will let you know if we learn more. We asked Lenovo why this seems to keep happening.
[14]
Ignoring that question, the PC maker told us: "The vulnerability reported by Lenovo and ESET has been mitigated and updates can be found [15]here . Customers who apply the update are not at risk.
"Lenovo works closely with all security researchers to provide responsible disclosure of vulnerabilities that protects customers by ensuring mitigations are in place before reporting. Lenovo thanks ESET for its professionalism and cooperation in reporting its findings." ®
Get our [16]Tech Resources
[1] https://twitter.com/ESETresearch/status/1547166334651334657
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YtCR-rruhHdeeH48zUsEaQAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtCR-rruhHdeeH48zUsEaQAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YtCR-rruhHdeeH48zUsEaQAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://support.lenovo.com/sk/en/product_security/len-91369
[6] https://support.lenovo.com/sk/en/product_security/len-91369#Lenovo%20Notebook
[7] https://www.theregister.com/2022/07/11/lenovo_secured_core/
[8] https://www.theregister.com/2022/06/27/lenovo_truscale_hardware_software/
[9] https://www.theregister.com/2022/06/23/lenovo_thinkstation_p360/
[10] https://www.theregister.com/2022/06/21/lenovo_barcelona_supercomputing_center/
[11] https://www.theregister.com/2022/04/19/eset_lenovo/
[12] https://t.co/HC5ow6KTN0
[13] https://twitter.com/ESETresearch/status/1547166341110669314?ref_src=twsrc%5Etfw
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtCR-rruhHdeeH48zUsEaQAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://support.lenovo.com/us/en/product_security/LEN-91369
[16] https://whitepapers.theregister.com/
For any who don't already know...
...go [1]here (https://pcsupport.lenovo.com/gb/en/) end enter your serial number and then go to the driver & software section. The auto download will find all drivers and firmware updates and install them using their app which will be/can be downloaded, or manually update from the list of available updates. Lenovo may be as shonky as most OEMs, but they do provide pretty much everything you might need to update or repair their kit yourself in terms of drivers and documentation, something I find certain other brands are a lot more reticent about.
(You may need to click the national flag at top right to select your local country)
[1] https://pcsupport.lenovo.com/gb/en/
Re: For any who don't already know...
Except their Service Bridge and Lenovo Updater keep flagging a BIOS update on our X131e "door wedges" yet NONE of the methods for downloading and installing the BIOS update work.
They all FAIL and have done for MONTHS.
Re: For any who don't already know...
The X131e (and all Thinkpads) isn't on the Lenovo list of laptops affected by this vulnerability (see link in article).
However, I've also had BIOS/NVME/UEFI updates that have failed on first attempt this year.
I found sequence to generally be reliable:
1. ensure all other updates have been installed
2. disable the AV software so that it doesn't restart on a reboot
3. as local admin, install only one BIOS etc. update at a time.
4. reboot and re-enable AV software.
Only issue I've had is that it has taken a couple of loops around (allow a few days between each iteration) to get the NVME update to install.
"asked Lenovo why this seems to keep happening"
ZING.
That's why I love El Reg so much.