The US Computer Emergency Readiness Team (US-CERT) today issued the following warning:
Lenovo consumer personal computers employing the pre-installed Superfish Visual Discovery software contain a critical vulnerability through a compromised root CA certificate. Exploitation of this vulnerability could allow a remote attacker to read all encrypted web browser traffic (HTTPS), successfully impersonate (spoof) any website, or perform other attacks on the affected system.
US-CERT recommends users and administrators review Vulnerability Note VU#529496 and US-CERT Alert TA15-051Afor additional information and mitigation details.