Looks like it took Microsoft 15 years to catch up to IBM on this one. IBM had this bug in AIX ‘cron’ back in 1992.
Anthony Ryan has discovered a bug in the Windows scheduler. Apparently it runs as System. You just run a simple command like:
at 13:38 /interactive “cmd.exe"
(where 13:38 is some time in the near future). You’ll get a command line that is running as the administrator.
Read his original blog for up to date information.
My IT folks at Cigital seem to have done whatever it takes to lock it down. Must be some default that they’ve set. This doesn’t work on laptops they issue.