CVE-2022-3699

HIGH EXPLOITED

Lenovo Diagnostics < 4.45.0 - Out-of-Bounds Write

Title source: rule

Description

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

Exploits (5)

nomisec WORKING POC 178 stars
by alfarom256 · local
https://github.com/alfarom256/CVE-2022-3699
nomisec WORKING POC 71 stars
by estimated1337 · local
https://github.com/estimated1337/lenovo_exec
nomisec WORKING POC
by Eap2468 · local
https://github.com/Eap2468/CVE-2022-3699
vulncheck_xdb WORKING POC
local
https://github.com/Marc-andreLabonte/AnalyseDynamiqueModulesKernel
metasploit WORKING POC GOOD
by alfarom256, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2022_3699_lenovo_diagnostics_driver.rb

Scores

CVSS v3 7.8
EPSS 0.8511
EPSS Percentile 99.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-12-19
CWE
CWE-787
Status published
Products (3)
lenovo/diagnostics < 4.45.0
lenovo/hardwarescan_addin < 2.4.1.1
lenovo/hardwarescan_plugin < 1.3.1.2
Published Oct 25, 2023
Tracked Since Feb 18, 2026