/// Known vulnerabilities, CVSS scores and affected products
Actively exploited vulnerabilitiesThe CISA KEV catalog lists vulnerabilities that are being exploited in real attacks, not ones that might be. It is the list to start from when deciding what to patch first.CVE database
- CVE-2004-0210High7.8
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
- CVE-2002-0367High7.8
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
This product uses the NVD API but is not endorsed or certified by the NVD.