Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.