CyberSec.Space Logo
Back to CVE Browser

CVE-2002-0367

Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score47.5310%
EPSS Percentile88.86th
PublishedJun 25, 2002
Last ModifiedApr 16, 2026

Vulnerability Description

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

Affected Platforms (CPE)

πŸ’»
Microsoft

Windows 2000

All versions
πŸ’»
Microsoft

Windows Nt

= 4.0
πŸ’»
Microsoft

Windows Nt

= 4.0

References & Advisories

Related Vulnerabilities