Lenovo BIOS Flaw Threatens ThinkPad Notebooks

When your operating system has a security vulnerability, you can patch it. When your BIOS — the basic input/output system controlling your computer's startup process — has a security vulnerability, fixing it is much more challenging.

Lenovo last week confirmed a potentially disastrous BIOS flaw that affects a wide range of Intel-based Lenovo laptops, including possibly all of the popular ThinkPad line, and may even extend to other computer manufacturers. A crafty cybercriminal could have a field day with this vulnerability.

Credit: Lenovo

(Image credit: Lenovo)

Information about the flaw comes from an independent security researcher Dmytro Oleksiuk, who posted his findings on GitHub last week. Lenovo did not seem happy about Oleksiuk posting the information before the company itself could, claiming "several unsuccessful attempts to collaborate with the researcher in advance of his publication."

MORE: Best Antivirus Software and Apps

Either way, the online cat is out of the digital bag, and it's bad news no matter how you slice it. Oleksiuk theorizes that a malicious hacker with access to the flaw could run arbitrary code, disable system-wide protections, install fake firmware and bypass authorization credentials on ThinkPads set up to run in an business, or "enterprise," configuration. (You could do these to home machines as well, although it probably wouldn't be worth the effort involved.)

Lenovo confirmed that the flaw is real, but insists that the company did not write the wayward code. Rather, it came from one of its independent BIOS vendors (IBVs), or third-party provider of BIOS software, although the company did not specify which one. Lenovo is currently trying to divine "the original purpose of the code."

Here's where the bad news gets worse: Lenovo "works with the industry's three largest IBVs," meaning that there's a good chance that non-Lenovo machines can fall prey to this flaw as well. Indeed, one of Oleksiuk's followers said he had confirmed the presence of the flaw in an HP laptop.

There's no telling how far back the vulnerability goes, although Oleksiuk claims to have found it in a ThinkPad X220 from 2011. Newer machines like the T450 possess it as well, so the malady has apparently not improved over time.

Until Lenovo addresses the root cause of the BIOS flaw, there's no fix available, and everyday users can't do anything to protect themselves. There's no evidence that cybercriminals have exploited the flaw in the wild, so there may not be cause for alarm. On the other hand, now that Oleksiuk has released the details, an enterprising malefactor might try to put that information to good (or, more accurately, bad) use.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Laptops
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
MacBook Air M4 vs MacBook Pro M4
MacBook Air M4 vs MacBook Pro M4 — I'll help you pick the best MacBook for your needs
Razer Blade
Nvidia's DLSS 4 demo in a Razer Blade 16 with RTX 5090 gives me hope again for next-gen gaming laptops
Asus ROG Zephyrus G16 shown with game controller
I wanted an RTX 50-series gaming laptop, but $620 off this Asus ROG Zephyrus G16 broke me
The Razer Blade 16 (2025) on a couch
Razer Blade 16 with RTX 5060 spotted in new leak — with a pretty shocking $1,999 price tag
HP OmniBook
HP’s new OmniBook lineup looks set to smash AI laptop price barriers — that’s a good thing if the company keeps up its end of the deal
Latest in News
Nintendo Switch 2
Nintendo Switch 2 tipster may have just leaked release month and launch plans
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
  • Terry_54
    This article smells fishy. It almost smells malicious on its own. Heavy handed tones towards Lenovo but just whispers regarding HP or other manufacturers also in the same boat.
    Reply