Lenovo laptops open to attack — what to do right now

ThinkPad
(Image credit: Tom's Guide)

Three security flaws in hundreds of Lenovo laptops could have exposed millions of users to potentially serious issues, security firm ESET announced today. These vulnerabilities would have allowed hackers to implant malware that would bypass a number 

Affected laptops include Lenovo Ideapads, Flex and Yoga notebooks, and Lenovo Legion gaming laptops. The good news is Lenovo has issued firmware updates for the affected models. Here's everything you need to know, and how to patch your laptop.

Three vulnerabilities found

ESET researcher Martin Smolár discovered three vulnerabilities in Lenovo laptops, and reported it to the company in October, 2021.

The first two vulnerabilities (CVE-2021-3971 and CVE-2021-3972) would have allowed an attacker with access to a laptop to install so-called UEFI malware — malicious code that activates during a notebook's startup, and can bypass built-in security protections. 

These vulnerabilities were a result of Lenovo accidentally leaving in place UEFI firmware drivers, where were meant to only be used during the manufacturing process, according to ESET. These drivers were left in the BIOS images that shipped to consumers. 

The third (CVE-2021-3970) was uncovered during ESET's investigation of the first two issues; this vulnerability would have allowed someone with direct access to a laptop to implant code in a machine's SMRAM. This could then be used to insert malware into a notebook's SPI flash memory chip, which also lets it bypass security protocols.

How to tell if your Lenovo laptop is affected and what to do

On Lenovo's support page, you can find a complete list of the laptops affected by these security vulnerabilities. They include the following models:

  • Ideapad 3 (14-, 15- and 17-inch models)
  • Flex 3
  • L340 gaming laptop
  • Legion 5
  • Legion 5 Pro
  • Legion 7
  • Legion S7
  • Legion Y540
  • Legion Y545
  • Legion Y7000
  • Lenovo S14 G2
  • Ideapad S145
  • Ideapad S540
  • Ideapad Slim 7 Pro
  • Ideapad Slim 9
  • V14 (G1 and G2)
  • Yoga 7
  • Yoga Slim 7 Pro
  • Yoga Slim 9

Lenovo provides links to the support pages for these affected laptops, where you can download the latest firmware updates. We install these updates ASAP so your system is protected. 

TOPICS
Mike Prospero
U.S. Editor-in-Chief, Tom's Guide

Michael A. Prospero is the U.S. Editor-in-Chief for Tom’s Guide. He oversees all evergreen content and oversees the Homes, Smart Home, and Fitness/Wearables categories for the site. In his spare time, he also tests out the latest drones, electric scooters, and smart home gadgets, such as video doorbells. Before his tenure at Tom's Guide, he was the Reviews Editor for Laptop Magazine, a reporter at Fast Company, the Times of Trenton, and, many eons back, an intern at George magazine. He received his undergraduate degree from Boston College, where he worked on the campus newspaper The Heights, and then attended the Columbia University school of Journalism. When he’s not testing out the latest running watch, electric scooter, or skiing or training for a marathon, he’s probably using the latest sous vide machine, smoker, or pizza oven, to the delight — or chagrin — of his family.

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Image of technical screen displaying system hacked warning
SonicWall VPN hit with second vulnerability
Lenovo Yoga Pro 9i and Yoga Pro 7i Aura Editions
Lenovo just gave two of its Yoga AI laptops a major Aura Edition upgrade – here’s all the new features
Latest in Laptops
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
MacBook Air M4 vs MacBook Pro M4
MacBook Air M4 vs MacBook Pro M4 — I'll help you pick the best MacBook for your needs
Razer Blade
Nvidia's DLSS 4 demo in a Razer Blade 16 with RTX 5090 gives me hope again for next-gen gaming laptops
Asus ROG Zephyrus G16 shown with game controller
I wanted an RTX 50-series gaming laptop, but $620 off this Asus ROG Zephyrus G16 broke me
The Razer Blade 16 (2025) on a couch
Razer Blade 16 with RTX 5060 spotted in new leak — with a pretty shocking $1,999 price tag
HP OmniBook
HP’s new OmniBook lineup looks set to smash AI laptop price barriers — that’s a good thing if the company keeps up its end of the deal
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Friday, March 28 (#656)
Reddit logo and Reddit logo on phone
Reddit, X and MLB.TV were down — live updates on outage
Nintendo Switch 2 console, Joy-Con controllers and dock
The Switch 2's mysterious "C" button may have just been confirmed by Nintendo
Nintendo Switch virtual game card
Nintendo just announced 'Virtual Game Cards' ahead of Switch 2 launch
Gerard Butler as Detective Nick "Big Nick" O'Brien in "Den of Thieves 2: Pantera"
Netflix top 10 movies — here’s the 3 worth watching right now
Graphic screen displaying malware detection warning
This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand