UMC Security Advisory: MFGSTAT

 UMC received a new advisory from Lenovo Product Security page about Improper File Permission on Lenovo PC Preloaded Windows OS which during manufacturing process, some Lenovo PCs with preloaded Windows operating systems included a file, MFGSTAT.zip, in the C:\Windows directory that is writable by standard user accounts.

The presence of this file only impacts customers who use third-party security software that is explicitly configured not to monitor the C:\Windows directory. Concerned customers should review their security tool configurations to determine if they are impacted.

United Metrolite Central will suspend temporarily for all current laptop fleets because were required to check the MFGSTAT.zip until files are removed and lift the suspension once removed the MFGSTAT.zip.

References:

Note:
This Lenovo article link is originally published on June 10, 2025 which last updated on July 18, 2025, which 7 months old. Please check the latest Lenovo Product Security page for more latest information.

Comments

Popular posts from this blog

UMC Security Advisory - Celxpert Battery Issues

How I Became a Proactive Battery Monitor (Catching Issues Early)

UMC Bans the DeepSeek amid security concerns