CVE-2002-0367
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-269
מוצרים מושפעים
microsoft: windows 2000; microsoft: windows nt
קישורים
- http://www.iss.net/security_center/static/8462.php Broken LinkPatchVendor Advisory
- http://www.securityfocus.com/archive/1/262074 Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-… PatchVendor Advisory
- http://www.iss.net/security_center/static/8462.php Broken LinkPatchVendor Advisory
- http://www.securityfocus.com/archive/1/262074 Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-… PatchVendor Advisory
- http://marc.info/?l=ntbugtraq&m=101614320402695&w=2 Mailing List
- http://www.securityfocus.com/archive/1/264441 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/264927 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/4287 Broken LinkThird Party AdvisoryVDB Entry