Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2002-0367
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
微软Windows 2000/NT 4.0调试子系统本地权限提升漏洞(MS02-024)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
微软Windows 2000和Windows NT 4存在一个漏洞,允许任意一个本地用户获取SYSTEM权限。 通过如下办法请求调试子系统(smss.exe)获取任意进程句柄、线程句柄的副本: 1) 调用DbgUiConnectToDbg()成为调试子系统客户端 2) 调用ZwConnectPort()连接DbgSsApiPort LPC port,任意用户都可以访问该端口 3) 调用ZwRequestPort()请求调试子系统处理CreateProcess SsApi,形参为欲复制的PID或TID 4)
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2002-0367
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2002-0367
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2002-0367

No comments yet


Leave a comment