Abuse of NIS instances

There is a possible to run unlimited instances of NIS.exe (with "/c /a /s UserSession" arguments) and they can't be killed (access denied).
This method can be used by malicious users to abuse the system, because all processes use computer's resources.

 

Sample:

Sample

 

As result we have many of unkillable processes.