CVE-2002-0367
KEVmassLocal Privilege Escalation in Microsoft Windows smss.exe Debugging Subsystem
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2002-0367 is a local privilege escalation flaw in the debugging subsystem of Microsoft Windows, in which the component associated with smss.exe does not properly authenticate programs that connect to other programs. A local attacker can exploit it by attaching to a process running with elevated rights, causing the unverified debugging connection to be accepted. Successful exploitation grants administrator or SYSTEM privileges on the affected machine, enabling full system control, credential theft, and follow-on activity such as ransomware deployment. All Microsoft Windows systems covered by CISA's advisory are affected; the source data does not specify exact version ranges, so defenders should consult the vendor advisory for scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating confirmed in-the-wild exploitation, with no public proof-of-concept identified and an EPSS 30-day exploitation probability of 4.9% (92nd percentile).
What to do: Apply Microsoft updates per vendor instructions, as required by CISA following the 2022-03-03 KEV listing. Because exploitation requires local access, restrict interactive logon and local program-installation rights on Windows systems, and audit legacy hosts to confirm the debugging-subsystem patch is installed.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows