Multiple Vulnerabilities Affected Lenovo’s Server Infrastructure that allows Hackers to Execute Malicious Code

Researchers discovered several vulnerabilities that affected Lenovo servers/application infrastructure that could have exploited the systems integrity, availability, and confidentiality.

Lenovo Group, one of the multinational technology company, sells personal computers, tablets, smartphones, workstations, servers, electronic storage devices.

Totally nine vulnerabilities were identified, in which, two vulnerabilities are categorized under High severity, and seven vulnerabilities are fixed under medium severity.

According to Swascan, In line with the spirit and objectives of Swascan, this press release is not intended to discuss or dissect the identified vulnerabilities. The purpose of this article, however, is to shift the focus on the importance of real collaboration between vendors and CyberSecurity companies.

Some of the Resolved  Vulnerabilities That Affected Lenovo Server Infrastructure

CWE – 78

This vulnerability allows attackers to execute the malicious command directly on the operating system. It exploits the Lenovo applications which don’t have direct access for attackers and also attacker-controlled commands may run with special system privileges.

CWE – 119:

A high severity vulnerability that resides in the memory buffer let attackers perform read or write operations to be performed on memory locations that may be associated with other variables, data structures, or internal program data. 

CWE-416:

In result, attackers execute an arbitrary code and read the sensitive information stored in the system and also leads to system crash.

This vulnerability allows function pointers is overwritten with an address to valid shellcode. Attackers taking advantage of this flaw and execute arbitrary code.

CWE-20:

The vulnerability resides in one of the Lenovo application let software improperly validate the input. Attacker taking advantage of this flaw and altered control flow, arbitrary control of a resource, or arbitrary code execution.

Swascan neither disclosed any details about the affected application nor depth information about the Lenovo infrastructure. All the Vulnerabilities are evaluated by the Lenovo security Team and fixed it.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Critical WiFi Buffer Overflow Vulnerability Impacts Lenovo Thinkpad Series Laptops

Lenovo Discovered a Backdoor in Network Switches Which Allows Attacker Could Perform DDOS

Lenovo VIBE Mobile Phones Vulnerable to Local Root Privilege Escalation – Its Time to Update your Lenovo Smart Phones

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Multiple Azure DevOps Vulnerabilities Let Inject CRLF Queries & Rebind DNS

Researchers uncovered several significant vulnerabilities within Azure DevOps, specifically focusing on potential Server-Side Request Forgery…

3 hours ago

Hackers Weaponize npm Packages To Steal Solana Private Keys Via Gmail

Socket’s threat research team has identified a series of malicious npm packages specifically designed to…

3 hours ago

Hackers Weaponize MSI Packages & PNG Files to Deliver Multi-stage Malware

Researchers have reported a series of sophisticated cyber attacks aimed at organizations in Chinese-speaking regions,…

4 hours ago

New IoT Botnet Launching Large-Scale DDoS attacks Hijacking IoT Devices

Large-scale DDoS attack commands sent from an IoT botnet's C&C server targeting Japan and other…

4 hours ago

Researchers Used ChatGPT to Discover S3 Bucket Takeover Vulnerability in Red Bull

Bug bounty programs have emerged as a critical avenue for researchers to identify vulnerabilities in…

5 hours ago

ChatGPT Crawler Vulnerability Abused to Trigger Reflexive DDoS Attacks

Security researchers have uncovered a severe vulnerability in OpenAI's ChatGPT API, allowing attackers to exploit…

6 hours ago