ZeroHour

CVE-2002-0367

KEVmass

Local Privilege Escalation in Microsoft Windows smss.exe Debugging Subsystem

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS
EPSS
5%p92
Published
KEV added
AI analysis

CVE-2002-0367 is a local privilege escalation flaw in the debugging subsystem of Microsoft Windows, in which the component associated with smss.exe does not properly authenticate programs that connect to other programs. A local attacker can exploit it by attaching to a process running with elevated rights, causing the unverified debugging connection to be accepted. Successful exploitation grants administrator or SYSTEM privileges on the affected machine, enabling full system control, credential theft, and follow-on activity such as ransomware deployment. All Microsoft Windows systems covered by CISA's advisory are affected; the source data does not specify exact version ranges, so defenders should consult the vendor advisory for scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating confirmed in-the-wild exploitation, with no public proof-of-concept identified and an EPSS 30-day exploitation probability of 4.9% (92nd percentile).

What to do: Apply Microsoft updates per vendor instructions, as required by CISA following the 2022-03-03 KEV listing. Because exploitation requires local access, restrict interactive logon and local program-installation rights on Windows systems, and audit legacy hosts to confirm the debugging-subsystem patch is installed.

Affected
Microsoft Windows
Estimated exposure
mass≈1B+ Windows devices historically (dominant desktop/server OS); currently unpatched legacy hosts unknown — Estimated from Windows' enormous installed base of more than a billion active devices, tempered by the fact that this is a 2002-era flaw fixed long ago, so the presently vulnerable population is an unknown subset of unpatched legacy…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows

In the news