Uncoordinated full disclosure of proof-of-concept (PoC) exploits
Time-of-Check to Time-of-Use (TOCTOU) race conditions
Abuse of NTFS directory junctions and opportunistic locks
Exploitation of Windows Recovery Environment (WinRE) configuration files (unattend.xml)
Manipulation of Windows User Profile service for cross-user registry hive loading
Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM