Zero Day Initiative - Breaking Barriers and Assumptions: Techniques for Privilege Escalation on Windows: Part 2
Briefly

...when the handle is opened with delete permissions, there is nothing done to prevent it from following any links a standard user could create...escalate our privileges to NT AUTHORITY\SYSTEM.
By polling the file for attribute changes, we now have a good indicator of when the file will be deleted...create our link, as the file's about to be deleted.
Read at Zero Day Initiative
[
]
[
|
]