As you all know Task Scheduler Service runs under the Local System Account.
Imagine this. . . . A Normal User with Minimal Rights does this.
In the Command Prompt types
at time xx:yy /interactive taskmgr.exe where xx:yy is the time the user Schedules to Run the above. Now the taskmgr.exe Starts with *Local System Account* at xx:yy . What can the user do now? In the File Menu, click New Task[Run] and do whatever (s)he wants to do under *System Account*.
I did not experiment with this yet. I thought I would check with you guys here and see what do you think.
-There Is A Foolish Corner In The Brain Of The Wisest Man- Aristotle
Re: Privilege Escalation To Local System Account
14 years 3 weeks ago #6042