SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2002-0367

Microsoft Windows Privilege Escalation Vulnerability

KEVHIGH 7.8EPSS 4.92%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
4.92% probability · 92th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Weakness
CWE-269
Affected
microsoft/windows 2000 · microsoft/windows nt
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2002-0367

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.