VULNERABILITY INTELLIGENCE
CVE-2002-0367
CVSS score7.8 HIGH
EPSS probability4.92%
CISA KEVKnown exploited vulnerability
Published2002-06-25
Last modified2026-06-16
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Known Exploited Vulnerability
Microsoft Windows Privilege Escalation Vulnerability
Vendor / product: Microsoft / Windows
Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
Weakness classification
- CWE-269: Improper Privilege Management
Primary references
- cve@mitre.org — Mailing List
- cve@mitre.org — Broken Link, Patch, Vendor Advisory
- cve@mitre.org — Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- cve@mitre.org — Broken Link, Third Party Advisory, VDB Entry
- cve@mitre.org — Broken Link, Third Party Advisory, VDB Entry
- cve@mitre.org — Broken Link, Third Party Advisory, VDB Entry
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org — Broken Link
- cve@mitre.org — Broken Link
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List
- af854a3a-2127-422b-91ae-364da2661108 — Broken Link, Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory