01-06-2018 12:43 PM - edited 01-06-2018 01:20 PM
We own several Lenovo G series - G50, G70 with Windows x64 8.1.
Under the Reading Privileged Memory with a Side Channel
Lenovo Security Advisory: LEN-18282
Potential Impact: Malicious code running locally may be able to observe contents of privileged memory, circumventing expected privilege levels.
Scope of Impact: Industry-wide CVE Identifier: “Spectre” CVE-2017-5753, CVE-2017-5715
such G Series seem not listed at all and no Target availability or Link to Update.
The step #3 of the Windows Client Guidance for IT Pros to protect against speculative execution side-channel vulnerabil... requires
3. Apply the applicable firmware update that is provided by the device manufacturer.
Windows Updates and January 2018 Windows security updates (step#2) are not enough, unfortunately.
We are quite worried about the flawed Intel CPUs design and the implications of these security risks.
Do you plan to release firmware upgrades for Meltdown & Spectre risks for the G Series, please? Thank you.
Do you own a G Serie Laptop? Reply to this thread and click over I have this question too.
01-09-2018 11:17 AM
I'm replying in order to follow - I have a G50-45 Laptop (type 80E3016QUS) and would like to know when I can expect a BIOS update.
01-10-2018 11:47 PM
01-12-2018 12:05 AM - edited 01-12-2018 01:26 AM
that's not a solution. I linked that security bulletin above.
As of today January 12, there is is not a Target availability for G-Series support!
Please ask for BIOS updates covering Spectre and Meltdown security risks for your G serie model.
01-12-2018 01:24 AM
01-12-2018 01:34 AM - edited 01-12-2018 01:41 AM
please specify your G serie model for BIOS/ firmware upgrade. Windows OS upgrades are not enough.
In short, about the risks:
Meltdown "basically melts security boundaries which are normally enforced by the hardware." Spectre, meanwhile, "breaks the isolation between different applications" allowing "an attacker to trick error-free programs, which follow best practices, into leaking their secrets."
And what does that actually mean? Essentially, either of these vulnerabilities could be theoretically exploited to steal sensitive data, like passwords, off your computer. Spectre is also a threat to your smartphone, so no escape there."
01-12-2018 03:44 AM
I have the G50-80 powered by Intel core I5 5200U and running on Windows 10 x64. Please release an update soon to fix the issue.
01-12-2018 04:19 AM
I've locked this thread because it is a duplication of an issue which is covered in the Security & Malware boards which makes this one redundant. Further duplicate topics and thread hijacks have also been removed.
Discussions on past and present Security Issues belong in the Security & Malware board.
Thank you for understanding.
English Community Leader
Please remember to come back and mark the post that you feel solved your question as the solution, it earns the member + points
Did you find a post helpfull? You can thank the member by clicking on the star below their post awarding them Kudos
Please don't ask me questions by Personal Message; questions belong in the forums.