The CSRSS BaseSrv RPC call BaseSrvCheckVDM allows you to create a new process with the anonymous token, which results on a new process in session 0 which can be abused to elevate privileges.
f24c7d593d547e23379c3440dbf5f7f452e40b8133e8dd3211fa702220bba978