CVE-2002-0367
Microsoft Windows Privilege Escalation Vulnerability
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
HIGH · CVSS 7.8
⚠ CISA KEV
EPSS 0.01453
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0