VulnerabilityAnalyzed
CVE-2002-0367
Microsoft Windows Privilege Escalation Vulnerability
KEVHIGH 7.8EPSS 4.92%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.92% probability · 92th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-269
- Affected
- microsoft/windows 2000 · microsoft/windows nt
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2002-0367
References
- http://marc.info/?l=ntbugtraq&m=101614320402695&w=2Mailing List
- http://www.iss.net/security_center/static/8462.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/262074Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/archive/1/264441Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/264927Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4287Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76Broken Link
- http://marc.info/?l=ntbugtraq&m=101614320402695&w=2Mailing List
- http://www.iss.net/security_center/static/8462.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/262074Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/archive/1/264441Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/264927Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4287Broken Link, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-024Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A158Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A76Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2002-0367US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.