Nazim from the IIS team has posted a detailed read on the Token Kidnapping in Windows.
http://blogs.iis.net/nazim/archive/2008/10/14/token-kidnapping-in-windows.aspx
It’s definitely worth reading if you are responsible for locking down machines.
Steve