CVE-2002-0367 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 4.9% (pctl 92)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.92% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | yes |
| Published | 2002-06-25 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Microsoft Windows Privilege Escalation Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Microsoft / Windows |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows 2000 |
| microsoft | windows nt |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows NT 4.0/2000 - Process Handle Local Privilege Escalation | 2002-03-13 |
References
- http://marc.info/?l=ntbugtraq&m=101614320402695&w=2
- http://www.iss.net/security_center/static/8462.php
- http://www.securityfocus.com/archive/1/262074
- http://www.securityfocus.com/archive/1/264441
- http://www.securityfocus.com/archive/1/264927
- http://www.securityfocus.com/bid/4287
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76
- http://marc.info/?l=ntbugtraq&m=101614320402695&w=2
- http://www.iss.net/security_center/static/8462.php
- http://www.securityfocus.com/archive/1/262074
- http://www.securityfocus.com/archive/1/264441
- http://www.securityfocus.com/archive/1/264927
- http://www.securityfocus.com/bid/4287
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367
→ the Explorer · watch your stack · NVD