September 29, 2009
Yes, the Performance Sentry collection service can impersonate a User Account to gain access to secure network resources.
By design, the Performance Sentry Collection Service (dmperfss.exe) is installed to run under the built-in LocalSystem (SYSTEM) account. This built-in account, which most services use, has the authority to perform almost any internal function on the local machine. [...]