Deleting the BCD through COM as low privileged user
During his research into Component Object Model (COM) and DCOM (Distrubuted COM), our colleague Remco stumbled upon a interesting vulnerability in the Windows SearchIndexer process. This vulnerability allowed a low privileged user (user without administrative privileges or any additional tokens), to let the SearchIndexer process delete all registry keys under the HKLM\BCD registry key, essentially making the system unbootable.