CVE-2002-0367

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:-:*:*:terminal_server:*:*:*

History

16 Jul 2024, 17:42

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:-:*:*:terminal_server:*:*:*
References () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - Mailing List
References () http://www.iss.net/security_center/static/8462.php - Patch, Vendor Advisory () http://www.iss.net/security_center/static/8462.php - Broken Link, Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/262074 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/archive/1/262074 - Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References () http://www.securityfocus.com/archive/1/264441 - () http://www.securityfocus.com/archive/1/264441 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/264927 - () http://www.securityfocus.com/archive/1/264927 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/4287 - () http://www.securityfocus.com/bid/4287 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - Patch, Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - Broken Link
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - Broken Link
CWE NVD-CWE-Other NVD-CWE-noinfo
CVSS v2 : 7.2
v3 : unknown
v2 : 7.2
v3 : 7.8

Information

Published : 2002-06-25 04:00

Updated : 2024-07-16 17:42


NVD link : CVE-2002-0367

Mitre link : CVE-2002-0367

CVE.ORG link : CVE-2002-0367


JSON object : View

Products Affected

microsoft

  • windows_nt
  • windows_2000