CVE-2022-3699
HIGH EXPLOITEDLenovo Diagnostics < 4.45.0 - Out-of-Bounds Write
Title source: ruleDescription
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
Exploits (5)
metasploit
WORKING POC
GOOD
by alfarom256, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2022_3699_lenovo_diagnostics_driver.rb
Scores
CVSS v3
7.8
EPSS
0.8511
EPSS Percentile
99.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-12-19
CWE
CWE-787
Status
published
Products (3)
lenovo/diagnostics
< 4.45.0
lenovo/hardwarescan_addin
< 2.4.1.1
lenovo/hardwarescan_plugin
< 1.3.1.2
Published
Oct 25, 2023
Tracked Since
Feb 18, 2026