The answer is certainly yes it can be done. We prevent all of these vectors (and a few others not mentioned) through the use of local group policy, NTFS and system level lockdowns.