Lenovo Computers Vulnerable to HTTPS Spoofing
Connectikpeople.co recalls that, Lenovo consumer personal computers
employing the pre-installed Superfish Visual Discovery software contain a
critical vulnerability through a compromised root CA certificate. Exploitation
of this vulnerability could allow a remote attacker to read all encrypted web
browser traffic (HTTPS), successfully impersonate (spoof) any website, or
perform other attacks on the affected system.
Therefore Connecikpeople.co recommends users and administrators to review
Vulnerability Note VU#529496 and US-CERT Alert TA15-051A for additional information and mitigation details.