Lenovo fixes hard-coded password in file-sharing utility
Lenovo has patched several software flaws in a file-sharing utility, which could allow attackers to browse and make copies of files.
The flaws were found by Core Security, which described in an advisory a lengthy back and forth dialog with Lenovo starting in late October over the problems.
The affected application is SHAREit, which is designed to let people share files from Windows computers or Android devices over a local LAN or through a Wi-Fi hotspot that’s created.
SHAREit is preloaded on Lenovo devices, including its ThinkPad and IdeaPad notebooks and other mobile devices. The vulnerable SHAREit versions are the Android 3.0.18_ww and Windows 188.8.131.52 packages, Core Security said.