We can look for what patches on windows are installed. If a host is poorly patched, you can get a easy priv esc without having to search for poor configurations in the system. The following lists all patches:
Windows Exploit Suggester compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also tells you if there are public exploits or metasploit modules on said exploit.
An [E] stands for an exploit has been found in the Off Sec exploit db, and an [M] stands for the exploit in the metasploit framework:
[M] MS15-100: Vulnerability in Windows Media Center Could Allow Remote
Code Execution (3087918) - Important
[E] MS14-026: Vulnerability in .NET Framework Could Allow Elevation of
Privilege (2958732) - Important