Junglewise Threat Intelligence

CVE-2002-0367: Microsoft Windows Privilege Escalation Vulnerability

CVE-2002-0367 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Windows, Microsoft Windows NT 4.0, Microsoft Windows 2000. Vendors: Microsoft.

Executive brief

The smss.exe debugging subsystem in Microsoft Windows NT and 2000 fails to properly authenticate programs connecting to other processes. Local attackers can exploit this by duplicating a handle to a privileged process, allowing for elevation of privilege to administrator or SYSTEM levels.

Affected products

  • Microsoft Windows 2000
  • Microsoft Windows NT 4.0

Timeline

  • 2002-05-22: advisory: Microsoft Security Bulletin MS02-024 published.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: NVD publication date.

Related threats