CVE-2022-3699PoC(lenovo / diagnostics)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for lenovo diagnostics systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • diagnostics
  • hardwarescan_addin
  • hardwarescan_plugin

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
diagnosticshardwarescan_addinhardwarescan_plugin

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-04-07: 1Technical Details · 2026-04-07: 104-07
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • impulsive@weezerOSINT
    PoC

    yeah i asked u that, and? u showed ur github and it proved my point for me. CVE-2022-3699, Lenovo Diagnostics Driver, arbitrary phys r/w via MmMapIoSpace thru ioctl 0x222010/0x222014. thats literally the same bug class ur calling a non-issue in my disclosure. and "mine was medium IL accessible" cool so was the DriversCloud driver i posted last week, zero security descriptor, any IL can open it. u just didnt read the thread before replying. we done

    Post summary

    The user presents a PoC and detailed exploit approach for CVE‑2022‑3699 on the Lenovo Diagnostics Driver, noting arbitrary physical read/write via specific IOCTLs, but does not report active exploitation or patch information.

    1000030
    2.6K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Applenovodiagnostics---
Applenovohardwarescan_addin---
Applenovohardwarescan_plugin---

Explore more