AppCompat, TLB invalidation, CPU specific issues vs. security?



Hello there, I have some questions regarding some implementation details.

1. By default the Application Experience Lookup service runs and automatically applies shim to known buggy applications, but also provides applying shims through the Application Compatibility plane, Application Compatibility Manager and QFixApp. Some shims are intended to bypass security mechanisms. My question: If running as an unprivileged user, does this allow to privilege escalation?

2. As documented in <http://www.intel.com/design/processor/applnots/317080.pdf>, Intel had to make some clarifications on how proper TLB cache invalidation is performed. Is this an issue for an up-to-date Windows Server 2003 SP2 kernel and if so, is a patch available?

3. Going further, on <http://www.intel.com/design/processor/applnots/31407918.pdf> there are some issues which might be applicable to either the NT kernel or VirtualPC's VMM. I'm especially looking at AH24, AH49, AH54, AH87, AH95, AH108, AH109, AH110, AH112, AH115, AH117 AH118, AH1P, AH2P and AH5P. Which of these is actually applicable and poses an issue?
.