Users who have Lenovo devices are requested to update their software to protect against the critical vulnerabilities discovered in their device.The company quietly rolled out patches for all vulnerabilities for all of its Android tablets, vibe and zuke p
Users who have Lenovo devices are requested to update their software to protect against the critical vulnerabilities discovered in their device. The company quietly rolled out patches for all vulnerabilities for all of its Android tablets, vibe and zuke phones on October 5. Imre Rad, an independent security researcher, discovered the vulnerabilities on May 10th and notified the bugs to the company on May 14th. Vulnerabilities were discovered in the Lenovo service framework (LSF) android application which is used by several different Android applications on Lenovo devices. Lenovo said LSF is used to receive a push notification from its servers regarding promotions for the app, news, notices, surveys. It is also used to facilitate emergency app repairs and upgrades when needed. Imre Rad said that LSF can be exploited by hackers to download code into their devices from an arbitrary server resulting in remote code execution.
You may be interested in reading: WPA2 protocol is vulnerable to eavesdropping - almost all devices are affected!Here are details of the vulnerabilities published on the website :
- CVE-2017-3758 – Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
- CVE-2017-3759 – The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
- CVE-2017-3760 – The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.
- CVE-2017-3761 – The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.