A researcher has published a method by which a local admin can hijack any other Windows sessions without the need for credentials.
Source: Threadpost