CISA KEV: CVE-2002-0367 - Microsoft Windows Privilege Escalation Vulnerability

CISA3/3/2022, 12:00:00 AM View Original
ransomwarecriticalransomwarevulnerabilitycvewindows

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Vendor: Microsoft Product: Windows Known ransomware use: Unknown Due date: 2022-03-24 https://nvd.nist.gov/vuln/detail/CVE-2002-0367

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Vendor: Microsoft Product: Windows Known ransomware use: Unknown Due date: 2022-03-24 https://nvd.nist.gov/vuln/detail/CVE-2002-0367