Makerere University

Enter a keyword or two into the search box above and click search..

Lenovo Computers Vulnerable to HTTPS Spoofing

You are here

Lenovo consumer personal computers employing the pre-installed Superfish Visual Discovery software contain a critical vulnerability through a compromised root CA certificate. Exploitation of this vulnerability could allow a remote attacker to read all encrypted web browser traffic (HTTPS), successfully impersonate (spoof) any website, or perform other attacks on the affected system.

Impact

A machine with Superfish VisualDiscovery installed will be vulnerable to SSL spoofing attacks without a warning from the browser.

DICTS recommends users and administrators review Vulnerability Note VU#529496 and Alert TA15-051A for additional information and mitigation details.

Category: