CVE-2002-0367
microsoft windows 2000, microsoft windows nt
Published 25 Jun 2002 · updated 16 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
References
- marc.info/?l=ntbugtraq&m=101614320402695&w=2 · Mailing List
- www.iss.net/security_center/static/8462.php · Broken Link, Patch, Vendor Advisory
- www.securityfocus.com/archive/1/262074 · Broken Link, Exploit, Patch
- www.securityfocus.com/archive/1/264441 · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/archive/1/264927 · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/4287 · Broken Link, Third Party Advisory, VDB Entry
- docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 · Patch, Vendor Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 · Broken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367 · US Government Resource