Live data from Hacker News

MS15-085 Vulnerability in Mount Manager Could Allow Elevation of Privilege

technet.microsoft.com

1–2 of 2 posts

Re: MS15-085 Vulnerability in Mount Manager Could Allow Elevation of Privilege

#2
So, plugging in a malicious USB storage device can not only execute malicious code, but can do it with elevated privileges.

Can it be done on a locked PC or must a user be actively logged in? I presume the former, as I don't believe the mounting process requires the PC to be unlocked.