More woe for Lenovo, Dell and Toshiba over laptop bloatware gone bad

Lenovo Ideapad 100S
Lenovo needs to buck its ideas up when it comes to security

Serious vulnerabilities have been uncovered in the pre-installed software (or bloatware, as it's commonly known) that comes with Lenovo notebooks, and also Dell and Toshiba laptops.

The findings come courtesy of slipstream/RoL (as spotted by the Register) who tweeted: "Three OEMs. Three applications preinstalled. Three exploits."

Lenovo – which let's face it, could really do without any further bad publicity regarding its pre-installed programs – has left a gaping hole in its Lenovo Solution Center, which is supposed to monitor system health and, ironically, security, allowing you to check up on antivirus and firewall status, and to update software.

Unfortunately, if you've got the Solution Center running and you visit a website which is loaded with an exploit, this can crack open your machine and run any code the attacker wants allowing for the installation of malware and a load of other potential nastiness.

Lenovo is aware of the situation (US-CERT chimed in on the matter) and has issued an update to say it's investigating the issue, with applicable fixes to come "as rapidly as possible". Meanwhile, users are advised to simply uninstall the Solution Center to ensure they don't fall victim to any malicious activity.

Bloatware bombshells

As for Dell, the flaw which affects its machines is in the Dell System Detect utility which can be exploited to gain admin privileges and run commands via a method which uses a security token that can be downloaded from Dell.com.

And when it comes to Toshiba, the vulnerability is present in the company's Service Station software and can apparently be exploited to read most of the registry of the OS. But that's certainly not on the level of the humdinger which Lenovo has been afflicted by.

Once again, this shines a spotlight on the dangers of loading machines with bloatware, which not only slows laptops down, but can present serious risks when the vendor in question can't take the necessary care and time to code its own programs with a decent level of security.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring