Vulnerability record · CVE-2002-0367 · published 25 June 2002
CVE-2002-0367: Windows NT/2000 smss.exe debugging subsystem privilege escalation
Microsoft · Windows 2000
The smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a local user to duplicate a handle to a privileged process. This lets an unprivileged local user escalate to administrator or SYSTEM rights, as demonstrated by the DebPloit tool. The flaw is a privilege management failure in a core Windows component.
Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to SYSTEM with KEV listing and an exploit reference, though limited to legacy Windows NT and 2000 systems.
What it is
The smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a local user to duplicate a handle to a privileged process. This lets an unprivileged local user escalate to administrator or SYSTEM rights, as demonstrated by the DebPloit tool. The flaw is a privilege management failure in a core Windows component.
Impact
An attacker with local access gains administrator or SYSTEM privileges on the affected host. That level of access permits full control of the machine, including disabling security controls and accessing sensitive data.
Attack surface
Reached locally by running a program that connects to and duplicates a handle from a privileged process; the CVSS vector AV:L/PR:L/UI:N indicates local access with low privileges and no user interaction. No remote or network vector is described.
Exploitation
CVE-2002-0367 is listed in CISA KEV (added 2022-03-03), and references include an Exploit tag, indicating known exploitation. EPSS 30-day probability is about 4.9 percent (91.7th percentile).
What to do
- Apply the Microsoft security update referenced in MS02-024 (patch first).
- Restrict local interactive and logon rights to trusted users only.
- Retire or isolate Windows NT and Windows 2000 systems that cannot be patched.
- Monitor for unauthorized handle duplication or debugging activity against privileged processes.
- Enforce least privilege so local users cannot run arbitrary code that targets privileged processes.
Detection
- Alert on local processes attempting to debug or duplicate handles to SYSTEM-owned processes.
- Monitor for creation of processes running as SYSTEM or administrator from unexpected parent processes.
- Audit local logon and privilege-use events for anomalies on NT/2000 hosts.
- Watch for known tooling such as DebPloit on endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2002-0367 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Windows Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0367 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.