Deleting the BCD through COM as low privileged user
During his research into Component Object Model (COM) and DCOM (Distrubuted COM), our colleague Remco stumbled upon an interesting vulnerability in the Windows SearchIndexer process. This vulnerability allowed a low privileged user (user without administrative privileges or any additional tokens), to let the SearchIndexer process delete all registry keys under the HKLM\BCD registry key, essentially making the system unbootable.