Executive brief
The smss.exe debugging subsystem in Microsoft Windows NT and 2000 fails to properly authenticate programs connecting to other processes. Local attackers can exploit this by duplicating a handle to a privileged process, allowing for elevation of privilege to administrator or SYSTEM levels.
Affected products
- Microsoft Windows 2000
- Microsoft Windows NT 4.0
Timeline
- 2002-05-22: advisory: Microsoft Security Bulletin MS02-024 published.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-03: disclosed: NVD publication date.