Lenovo's Service Engine marks yet another bloatware blunder for the company

By preventing laptops and desktops from performing a truly clean install of Windows, Lenovo may have left users open to attack.

Lenovo isn't doing its reputation any favors with the discovery of another security issue around its pre-loaded PC software.

The latest issue relates to a "feature" in Lenovo's BIOS firmware that automatically downloads Lenovo software and services, even if the user has performed a clean install of Windows. Microsoft actually allows this practice, but Lenovo's particular implementation -- dubbed "Lenovo Service Engine" -- led to a security vulnerability, which an independent security researcher discovered in the April to May timeframe.

In response, Microsoft has put out security guidelines for this BIOS technique, which it calls the "Windows Platform Binary Table." Because Lenovo Service Engine doesn't meet those guidelines, Lenovo has stripped the tool from its BIOS firmware in all PCs shipped after June. The company has also released a special disabler tool, and on July 31 released a BIOS update to remove the tool from existing PCs. Dozens of consumer laptop and desktop models are affected, but Lenovo says its Think-brand PCs are not.

Why this matters

There are a couple points of concern here. First is the vulnerability itself, which has flown under the radar for months. But just as troubling is the Microsoft-sanctioned mechanism that Lenovo was using to insert its software onto clean Windows installs. (One user on HackerNews described is a "rootkit-like" technique.) It's entirely possible that other PC vendors are relying on the same mechanism for sneakily installing their own software, but just haven't run into the same security issues that Lenovo did.

A brief history of Lenovo security woes

The timing is particularly poor for Lenovo, as it's just coming off another security scandal related to bloatware. In January, researchers discovered that a pre-loaded program called Superfish Visual Discovery was able to inject advertisements into the user's web browser. In the process, Superfish was overriding the security certificates that many websites use to encrypt their data, creating a weakness that could make banking credentials and other sensitive information available to hackers.

Lenovo eventually admitted that it messed up, pushed an update that removed Superfish from affected PCs, and vowed to significantly cut down on the amount of bloatware it installs on laptops and desktops. Still, the company faces a lawsuit over the whole ordeal.

The Lenovo Service Engine issue is unrelated, though it contains at least a whiff of the creepiness that got Lenovo in trouble last time. As The Next Web points out, the software installed by Lenovo Service Engine didn't just include updates to drivers, firmware, and pre-installed apps, but also sent "system data to a Lenovo server to help us understand how customers use our products." While Lenovo says it's not collecting personally identifiable information, the collection itself may be something customers aren't aware of, and until now haven't had any control over.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags MicrosoftsoftwareLenovobeca

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jared Newman

PC World (US online)
Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Family Friendly

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Stocking Stuffer

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?