Lucene search

K
cve[email protected]CVE-2002-0367
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0367

2003-04-0205:00:00
web.nvd.nist.gov
833
In Wild
2
windows nt
windows 2000
smss.exe
debugging
vulnerability
privilege escalation
cve-2002-0367
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.5%

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

Affected configurations

NVD
Node
microsoftwindows_2000
OR
microsoftwindows_ntMatch4.0

Social References

More

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.5%