目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2022-3699 PoC — Lenovo Diagnostics 缓冲区错误漏洞

来源
关联漏洞
标题: Lenovo Diagnostics 缓冲区错误漏洞 (CVE-2022-3699)
Description:Lenovo Diagnostics是中国联想(Lenovo)公司的是联想电脑的扫描以及诊断硬件故障工具。该工具可帮助用户对电脑进行扫描、检查、对电脑的司机问题进行修复的操作,Lenovo Diagnostics还可以帮助用户轻松解决电脑出现的一些蓝屏、死机问题进行修复,能够一键扫描并诊断故障。 Lenovo Diagnostics Driver存在缓冲区错误漏洞,该漏洞源于访问控制不正确。攻击者利用该漏洞可以执行任意物理或虚拟内存的读取和写入。
Description
Proof of Concept exploit for CVE-2022-3699
介绍
# CVE-2022-3699
Proof of Concept exploit for CVE-2022-3699

Exploit tested on Windows 10 22H2 build 19045.4651 and build 19045.3803

Vulnerability deals with allowing unprivileged users to access functionality that lets you read and write from physical memory from the instance of the kernel, however since the primitives deal with physical memory there's a bit of extra work needed to weaponize it

Stole the idea for getting the virtual read primitive from alfarom256 who got it from ch3rn0byl

![image](https://github.com/user-attachments/assets/20cbf2a5-85c4-4e7e-a807-ccadd12b2ca8)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →