Lenovo Patches Alarming UEFI Exploits Affecting Over 100 Laptops, Update ASAP
If you're confused, Lenovo published a document on April 18th warning its customers of three severe vulnerabilities in its system firmware across a wide variety of its consumer laptops. (None of the ThinkPad or ThinkBook models are affected.) These vulnerabilities could allow a local attacker to modify the firmware, allowing them to embed malware directly into the system board's UEFI eprom.
Fortunately, just four days later, Lenovo has patches available for most of the affected systems. You can head over to Lenovo's site to check your specific model to see if you're affected. A simple BIOS update is all that's required to fix the issues.