← Back to CVE List
Vulnerability Intelligence Report
Microsoft Windows Privilege Escalation Vulnerability

CVE-2002-0367

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:5.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-269 ↗CWE-269 Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
microsoft windows_2000 all
microsoft windows_nt 4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
5.188%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2002-05-08T00:00:00
Published2003-04-02T05:00:00
Patch Date2002-03-14
Last Updated2025-10-22T00:05:57

LINK COPIED TO CLIPBOARD