Lenovo Security Flaw Could Affect Millions: What to Do Now

Owners of older Lenovo laptops need to uninstall the Lenovo Solution Center as soon as possible. 

Security researchers at Pen Test Partners found a critical vulnerability in the Lenovo Solution Center that could hand admin privileges over to hackers or malware.

According to Pen Test Partners, the flaw is a discretionary access control list (DACL) overwrite, which means a low-privileged user can sneak into a sensitive file by exploiting a high-privileged process. This is an example of a "privileged escalation" attack in which a bug can be used to gain access to resources that are normally only accessible to admins. 

In this case, an attacker could write a pseudo-file (called a hard link file) that, when run by Lenovo Solution Center, would access sensitive files it otherwise shouldn't be allowed to reach. From there, damaging code could be executed on the system with administrator or system privileges, which is basically game over, as Pen Test Partners notes.

Lenovo Solution Center is a program that was preinstalled on Lenovo laptops from 2011 up until November 2018, which means millions of devices could be affected. Ironically, the program's purpose is to monitor the health and security of a Lenovo PC. While this flaw isn't such a big concern for individual users who can quickly protect their systems, larger companies who own a fleet of older ThinkPad laptops and use legacy software might be slow to adapt. 

For its part, Lenovo published a security statement warning users about the bug and urging them to uninstall Solution Center, which the company no longer supports. 

"A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or Lenovo Diagnostics in April 2018," reads the statement.

Lenovo didn't specify when it stopped shipping laptops with Solution Center pre-installed, so it's possible that many Lenovo laptops that are less than one year old carry unsupported software with major flaws.

Lenovo has also been accused of covering its tracks. According to Pen Test Partners, after they informed Lenovo of the vulnerability, the computer maker allegedly rolled back Solution Center's end-of-life date by several months to make it seem like the feature was discontinued before the last version was released in November 2018. 

"It’s often the case for applications that reach end of support that we continue to update the applications as we transition to new offerings is to ensure customers that have not transitioned, or choose not to, still have a minimal level of support, a practice that is not uncommon in the industry," Lenovo told The Register when asked about the discrepancy. 

Whether Lenovo is being sly or not, the bottom line is this: if you own a Lenovo laptop manufactured between 2011 and 2018, then absolutely get rid of Lenovo Solution Center as soon as possible. You can do so by following this simple guide on how to uninstall programs on Windows 10

Laptop Magazine has reached out to Lenovo for comment, and we will update this story when we receive a reply.

Phillip Tracy

Phillip Tracy is the assistant managing editor at Laptop Mag where he reviews laptops, phones and other gadgets while covering the latest industry news. After graduating with a journalism degree from the University of Texas at Austin, Phillip became a tech reporter at the Daily Dot. There, he wrote reviews for a range of gadgets and covered everything from social media trends to cybersecurity. Prior to that, he wrote for RCR Wireless News covering 5G and IoT. When he's not tinkering with devices, you can find Phillip playing video games, reading, traveling or watching soccer.

Latest in Laptops
Silver Surface Laptop 7 laptop against a blue gradient background.
Amazon Big Spring Sale continues with $250 price slash on the Surface Laptop 7
The HP Victus 16 on a wood table with a blue duotone background beside a Laptop Mag deals icon
The HP Victus 16 is one of the best-value gaming laptops I've ever reviewed. And it's $600 off right now.
Lenovo Legion 5i Gen 9 against blue gradient background with epic deal sticker.
The excellent Lenovo Legion 5i RTX 4070 gaming laptop hits its lowest price since Prime Day for Amazon's Big Spring Sale
Gameplay on the Razer Blade 16 (2025) with an Nvidia RTX 5090 Laptop GPU.
The RTX 5090 was supposed to be the chosen one, but does the RTX 4090 have the high ground?
Gameplay on the Razer Blade 16 (2025) with an Nvidia RTX 5090 Laptop GPU.
RTX 5090 Laptop GPU performance: The frame-gen future has arrived
Silver HP Laptop with epic deal sticker against a blue gradient background.
This epic Walmart Super Savings Week deal slashes $500 off the HP Envy Laptop 17
Latest in News
A close-up of a light-colored computer keyboard shows the keys T, Y, G, and H replaced by the logos of OpenAI, DeepSeek, Grok, and Gemini, the leading competitors in the artificial intelligence market. This serves as a visual metaphor for the intense rivalry and innovation in the AI industry. (Photo by Matteo Della Torre/NurPhoto via Getty Images)
Is generative AI inadvertently reducing the voices of many to the banality of one?
Asus ROG Ally Z1 on a brown table with the game Unpacking played on screen.
Handheld gaming PCs have a Windows problem — but maybe not for long
WWDC 2025 could mark the beginning of the end for certain iPhone users
Error when installing Google Chrome on the Asus Vivobook 16 Flip, on a white desk against a blue background.
"This app can't run on your PC": Google's Chrome Installer broke on Windows, but there's a fix
Nintendo Switch 2 handheld gaming console
Nintendo Switch 2 preorder date: It might be a lot closer than you think, say tipsters
Microsoft Surface Laptop (7th Edition, 2024)
Windows-on-Arm woes: Amazon warns customers about Surface laptop returns