Plenty, Microsoft has security teams whose job is to attack Windows.
Naturally they don't do blog posts about what they find.
Local privilege escalation is largely irrelevant on Windows because basically no one uses it in a multi-user system, and application sandboxing is effectively nonexistent.
You talk as if Windows is the only OS that has red teams attacking the system when clearly that isn’t even remotely true.
Local privilege escalation is largely irrelevant on Windows because basically no one uses it in a multi-user system, and application sandboxing is effectively nonexistent.