First published: Tue Oct 24 2023(Updated: )
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Diagnostics | <4.45.0 | |
Lenovo Hardwarescan Addin | <2.4.1.1 | |
Lenovo Hardwarescan Plugin | <1.3.1.2 |
Update to Lenovo Diagnostics Application v4.45 or later. Update the Lenovo HardwareScan Plugin to version 1.3.1.2 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3699 is a privilege escalation vulnerability in the Lenovo HardwareScanPlugin and Lenovo Diagnostics software.
The severity of CVE-2022-3699 is high, with a severity value of 7.8.
CVE-2022-3699 affects Lenovo HardwareScanPlugin versions prior to 1.3.1.2, allowing a local user to execute code with elevated privileges.
CVE-2022-3699 affects Lenovo Diagnostics versions up to 4.45.0, allowing a local user to execute code with elevated privileges.
You can find more information about CVE-2022-3699 on the Lenovo product security website: [https://support.lenovo.com/us/en/product_security/LEN-102365](https://support.lenovo.com/us/en/product_security/LEN-102365) and [https://support.lenovo.com/us/en/product_security/LEN-94532](https://support.lenovo.com/us/en/product_security/LEN-94532).