https://www.reddit.com/r/netsec/comm...nfhn?context=3
The programming error that allows escalation isn't in Windows, it's in *crypt.