CVE-2000-0737

Windows 2000 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0737. PoCs published by Maceo.

AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in Windows 2000 by creating a named pipe with a predictable name before the Service Control Manager (SCM) does, allowing the attacker to impersonate a service running as SYSTEM and dump the SAM database.

Description

The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Maceo · c++localwindows
https://www.exploit-db.com/exploits/20133

This exploit demonstrates a local privilege escalation vulnerability in Windows 2000 by creating a named pipe with a predictable name before the Service Control Manager (SCM) does, allowing the attacker to impersonate a service running as SYSTEM and dump the SAM database.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows 2000
Auth required
Prerequisites: Local interactive access to a Windows 2000 machine · Ability to stop and start the ClipBook service
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1535

Scores

EPSS 0.0157
EPSS Percentile 82.0%

Details

Status published
Products (1)
microsoft/windows_2000
Published Oct 20, 2000
Tracked Since Feb 18, 2026