Older Intel and Lenovo Hardware Has Hackable Firmware Bugs That Will Never Be Fixed, Researchers Find

Spread the love


Some Intel and Lenovo merchandise and options have an unfixable bug of their firmware that would let the tools to be hacked. The bug in concern has sat unpatched for a number of years and can by no means ever be patched primarily as a result of the impacted objects have been thought-about “end-of-life” and won’t obtain any further pc software program updates. Whereas the vulnerability is main loads of to make it potential for a unfavorable actor to chain it to a way more refined exploit, it doesn’t, by itself, present considerably of a hazard.

This week, the protection group Binarly launched a report concerning the security issues, which revolve all-around Lighttpd—a versatile, open up-supply web site server that’s utilized in myriad tech merchandise, along with firmware parts. A number of years in the past, within the summertime of 2018, a remotely exploitable software vulnerability was discovered inside Lighttpd by its maintainers that would have hypothetically allowed a savvy cybercriminal to entry vital security info and info.

Lighttpd’s software program program maintainers quietly issued a care for of their private code, Binarly researchers said, however they didn’t formalize it through a CVE—a standard vulnerabilities and exposures identifier—which might have permitted companies using the appliance to appropriate the issue. Lighttpd is utilised in numerous objects, which incorporates all these developed by American Megatrends Worldwide (AMI), a agency that generates considerably of the firmware software that essential suppliers depend on.

The trickle-down result’s that specific types of {hardware}—together with a number of merchandise made by Lenovo and Intel—by no means bought the cope with and, for that cause, are even now inclined to the bug. Now, individuals impacted devices will by no means ever be mounted, Binarly scientists declare, as a result of their distributors aren’t pushing out program updates for them anymore.

See also  Supercharge Your Storage with the Samsung 990 EVO SSD Up to 47% Off This Prime Day—Act Fast!

When reached for remark, Lenovo said it’s “conscious of the AMI MegaRAC concern recognized by Binarly” and that it’s “working with our provider to ascertain any potential impacts to Lenovo merchandise and options.” Intel, within the meantime, defined that the “affected system is for the time being finish-of-daily life, meaning no practical, security, or different updates will likely be supplied.”

Ars Technica notes that “the severity of the lighttpd vulnerability is just reasonable and is of no value except an attacker has a functioning exploit for a a lot further extreme vulnerability.” Binarly researchers have talked about {that a} “potential attacker can exploit this vulnerability in an effort to learn by way of reminiscence of Lighttpd World large internet Server plan of action,” which may result in “delicate info exfiltration, these sorts of as reminiscence addresses” and “can be utilized to bypass safety mechanisms this sort of as ASLR.” For that cause, the bug would floor to be way more of a leaping-off place for a much more subtle assault, even supposing it plainly presents a possibility for intrusion and, sooner or later, compromise.

best barefoot shoes

Supply website link

  • David Bridges

    David Bridges

    David Bridges is a media culture writer and social trends observer with over 15 years of experience in analyzing the intersection of entertainment, digital behavior, and public perception. With a background in communication and cultural studies, David blends critical insight with a light, relatable tone that connects with readers interested in celebrities, online narratives, and the ever-evolving world of social media. When he's not tracking internet drama or decoding pop culture signals, David enjoys people-watching in cafés, writing short satire, and pretending to ignore trending hashtags.

    Related Posts

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Money Robot Submitter Review 2026 Money Robot Submitter Review: Powerful Backlink Automation — But Is It Worth…

    Read more

    Prime Day 2026: Amazon Reveals Sale Dates

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Amazon has officially announced that its highly anticipated 12th annual Prime Day event will take place from…

    Read more

    You Missed

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Prime Day 2026: Amazon Reveals Sale Dates

    Prime Day 2026: Amazon Reveals Sale Dates

    Meta AI Provides Hackers Access to Instagram Accounts

    Meta AI Provides Hackers Access to Instagram Accounts

    Sydney Sweeney & Scooter Braun: Are They Still Together?

    Sydney Sweeney & Scooter Braun: Are They Still Together?

    Twitter Settlement Declared ‘Fair and Reasonable’ by SEC

    Twitter Settlement Declared ‘Fair and Reasonable’ by SEC

    ExpertBook B5 Flip G2: Lightweight 2.9 lb 360° Touchscreen Laptop

    ExpertBook B5 Flip G2: Lightweight 2.9 lb 360° Touchscreen Laptop

    Expecting Child: Waka Flocka Shares Exciting News

    Expecting Child: Waka Flocka Shares Exciting News

    AI Support Bot Exposes Instagram Accounts to Hackers

    AI Support Bot Exposes Instagram Accounts to Hackers

    Screen-Free Summer: Essential Guide for Parents of Kids

    Screen-Free Summer: Essential Guide for Parents of Kids

    A.J. Brown’s Eagles Exit Sparks Twitter Reactions

    A.J. Brown’s Eagles Exit Sparks Twitter Reactions