A default installation of Windows 7/8 can be made to perform a NTLM reflection attack through WebDAV which allows a local user to elevate privileges to local system.
more here...........https://code.google.com/p/google-security-research/issues/detail?id=222
more here...........https://code.google.com/p/google-security-research/issues/detail?id=222