4 ms·
What is amazing is that despite updates, Lenovo still hasn’t fixed the gaping security flaw affecting almost all Thinkpads. https://github.com/Cr4sh/ThinkPwn h
by joewee 8y ago
What is amazing is that despite updates, Lenovo still hasn’t fixed the gaping security flaw affecting almost all Thinkpads.
https://github.com/Cr4sh/ThinkPwn https://github.com/Cr4sh/ThinkPwn
You can’t trust thinkpads for security.
- mehrdadn 8y agoYou sure? I don't see the T470+ series on the vulnerability list: https://support.lenovo.com/us/en/solutions/len-8324 https://support.lenovo.com/us/en/solutions/len-8324
- joewee 8y agoThat list hasn’t been updated since 2016, but they continue to ship vulnerable firmware. Including in all bios updates since 2016. You would have to dump an image of your bios firmware using chipsec to confirm for yourself. https://github.com/chipsec/chipsec https://github.com/chipsec/chipsec
- bubblethink 8y agoThey did patch the reported vulnerabilities in updates. What chipsec reports as warnings are not necessarily exploitable. i.e., They didn't patch them to the extent of getting all green ticks in chipsec, but it does not automatically imply exploitable.
- joewee 8y agoOk. Thanks. I haven’t actually tried to run the PoC against it.