CVE-2002-0367

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
References
Link Resource
http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 Mailing List
http://www.iss.net/security_center/static/8462.php Broken Link Patch Vendor Advisory
http://www.securityfocus.com/archive/1/262074 Broken Link Exploit Patch Third Party Advisory VDB Entry Vendor Advisory
http://www.securityfocus.com/archive/1/264441 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/264927 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/4287 Broken Link Third Party Advisory VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 Broken Link
http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 Mailing List
http://www.iss.net/security_center/static/8462.php Broken Link Patch Vendor Advisory
http://www.securityfocus.com/archive/1/262074 Broken Link Exploit Patch Third Party Advisory VDB Entry Vendor Advisory
http://www.securityfocus.com/archive/1/264441 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/264927 Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/4287 Broken Link Third Party Advisory VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:-:*:*:terminal_server:*:*:*

History

20 Nov 2024, 23:38

Type Values Removed Values Added
References () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - Mailing List () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - Mailing List
References () http://www.iss.net/security_center/static/8462.php - Broken Link, Patch, Vendor Advisory () http://www.iss.net/security_center/static/8462.php - Broken Link, Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/262074 - Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/archive/1/262074 - Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References () http://www.securityfocus.com/archive/1/264441 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/264441 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/264927 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/264927 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/4287 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/4287 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - Patch, Vendor Advisory () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - Patch, Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - Broken Link
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - Broken Link

16 Jul 2024, 17:42

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:-:*:*:terminal_server:*:*:*
References () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - () http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 - Mailing List
References () http://www.iss.net/security_center/static/8462.php - Patch, Vendor Advisory () http://www.iss.net/security_center/static/8462.php - Broken Link, Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/262074 - Exploit, Patch, Vendor Advisory () http://www.securityfocus.com/archive/1/262074 - Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References () http://www.securityfocus.com/archive/1/264441 - () http://www.securityfocus.com/archive/1/264441 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/264927 - () http://www.securityfocus.com/archive/1/264927 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/4287 - () http://www.securityfocus.com/bid/4287 - Broken Link, Third Party Advisory, VDB Entry
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024 - Patch, Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158 - Broken Link
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76 - Broken Link
CWE NVD-CWE-Other NVD-CWE-noinfo
CVSS v2 : 7.2
v3 : unknown
v2 : 7.2
v3 : 7.8

Information

Published : 2002-06-25 04:00

Updated : 2024-11-20 23:38


NVD link : CVE-2002-0367

Mitre link : CVE-2002-0367

CVE.ORG link : CVE-2002-0367


JSON object : View

Products Affected

microsoft

  • windows_2000
  • windows_nt