SecHole lets non-administrative users gain Debug Level access

Risk Level: High risk vulnerability  High

Check or Attack Name: NTPrivFix

Platforms: Windows NT: 3.5, Windows NT: 4.0

The sechole.exe utility circulated on the Internet can allow a non-administrative user to gain debug-level access on a system process. Using this utility, the non-administrative user may run some code in the system security context and acquire local administrative privileges on the system.


Apply the latest Windows NT 4.0 Service Pack. To apply the latest Windows NT Service Pack, follow these steps:

  1. Open a web browser.
  2. Go to and follow the directions to download the appropriate service pack for your computer.
  3. Find the installation program you downloaded to your computer.
  4. Double-click the program icon to start the installation.
  5. Follow the installation directions.


Windows NT 4.0 Service Pack 3 (SP3) users must apply the post-SP3 priv-fix patch available from


Windows NT 3.51 SP5 customers can download the patch from


Microsoft Knowledge Base Article Q190288, SecHole Lets Non-administrative Users Gain Debug Level Access,

Microsoft Knowledge Base Article Q190288, SecHole Lets Non-administrative Users Gain Debug Level Access, public/fixes/usa/NT40/hotfixes-postSP3/priv-fix/Q190288.TXT hotfixes-postSP5/priv-fix/.

Microsoft Knowledge Base Article Q190288, SecHole Lets Non-administrative Users Gain Debug Level Access, otfixes-postSP3/priv-fix/

Microsoft Security Bulletin MS98-009, Update Available for Windows NT Privilege Elevation attack,

X-Force Logo
Know Your Risks