CISA Known Exploited Vulnerability

CVE-2002-0367

Microsoft · Windows

Microsoft Windows Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

Required action

Apply updates per vendor instructions.