Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.