Exploitation Summary
EIP tracks 1 public exploit for CVE-2000-0737. PoCs published by Maceo.
AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in Windows 2000 by creating a named pipe with a predictable name before the Service Control Manager (SCM) does, allowing the attacker to impersonate a service running as SYSTEM and dump the SAM database.
Description
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.
Exploits (1)
This exploit demonstrates a local privilege escalation vulnerability in Windows 2000 by creating a named pipe with a predictable name before the Service Control Manager (SCM) does, allowing the attacker to impersonate a service running as SYSTEM and dump the SAM database.