smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
Use CWE-269, Microsoft vendor hub and Windows 2000 product page to widen CVE-2002-0367 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2010-1880, CVE-2010-1262 and CVE-2010-1259 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.