The SecLogon service does not sanitize standard handles when creating a new process leading to duplicating a system service thread pool handle into a user accessible process. This can be used to elevate privileges to Local System.
1503dd54222782a3e53678913f5880565b05a932180f2498066832dd8aed5905