SP 52403: Protection of Internal System Objects is currently disabled
Symptom: If a non-administrative level user logs on interactively to your computer, it may be possible for the user to gain local administrative privileges.
Resolution: Modify the system registry settings to enable the protection policy for Internal System Objects.
Additional Information: This policy setting determines the strength of the default Discretionary Access Control List (DACL) for objects. Each type of object is created with a default DACL that specifies who can access the objects and what permissions are granted.
Category:
Security
