CVE-2002-0367

CVE Published 2002-06-25
Related Vendor(s) microsoft
Related Product(s) windows_2000, windows_nt
Exploitation Reported (CISA KEV) 2022-03-03
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References