← All CVEs

CVE-2002-0367

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

7.8
CVSS
4.9%
EPSS (exploit prob.)
92nd
EPSS percentile
2002-06-25
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-269

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_nt4.0
microsoftwindows_nt4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0367