This is Tavis's "thing" (one of them, at least); he's better known for fuzzing the device virtualization code in VMware and Xen and finding hypervisor escapes. I'm not even a little surprised that he found privilege escalation in VDM.<p>It's a cool bug, but it's a bit strange to see it get written up like this, because it doesn't matter a whole lot. On most Windows machines, if you have a normal user account, you have everything you need; in corporate environments, if you have one admin password you probably have all of them; in servers, the user account you bust is probably a local admin.