Vulnerability Name: | CVE-2002-0367 (CCN-8462) | ||||||||||||
Assigned: | 2002-03-14 | ||||||||||||
Published: | 2002-03-14 | ||||||||||||
Updated: | 2018-10-12 | ||||||||||||
Summary: | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. | ||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 14 2002 - 17:43:31 CST Fwd: DebPloit (exploit) Source: CCN Type: BugTraq Mailing List, Wed Mar 27 2002 - 04:01:58 CST Local Security Vulnerability in Windows NT and Windows 2000 Source: MITRE Type: CNA CVE-2002-0367 Source: NTBUGTRAQ Type: UNKNOWN 20020314 DebPloit (exploit) Source: CCN Type: CIAC Information Bulletin M-083 Microsoft Authentication Flaw in Windows Debugger Source: CCN Type: Defendion Web site EliCZ's Source: XF Type: Patch, Vendor Advisory win-debug-duplicate-handles(8462) Source: CCN Type: Microsoft Security Bulletin MS02-024 Authentication Flaw in Windows Debugger can Lead to Elevated Privileges (Q320206) Source: CCN Type: OSVDB ID: 788 Microsoft Windows smss.exe Handle Duplication Local Privilege Escalation Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20020314 Fwd: DebPloit (exploit) Source: BUGTRAQ Type: UNKNOWN 20020326 Re: DebPloit (exploit) Source: BUGTRAQ Type: UNKNOWN 20020327 Local Security Vulnerability in Windows NT and Windows 2000 Source: BID Type: UNKNOWN 4287 Source: CCN Type: BID-4287 Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability Source: MS Type: UNKNOWN MS02-024 Source: XF Type: UNKNOWN win-debug-duplicate-handles(8462) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:158 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:76 Source: CCN Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY KNOWN EXPLOITED VULNERABILITIES CATALOG | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |