← KEV catalog
CISA known exploited vulnerability

CVE-2002-0367

Microsoft Windows Privilege Escalation Vulnerability

SOURCE FACT

Microsoft · Windows

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2002-0367

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?