top | item 6665542

(no title)

doug11235 | 12 years ago

> So your arbitrary code is running as admin - what more could a security flaw in the bundled installshield get you?

In the days of Antivirus products and executable whitelists, the "elevation of privilege" may be getting arbitrary execution as any user. Of course trustedinstaller.exe or whatever that has a valid Microsoft signature can run, why shouldn't it? No need to ship that file back home either for further analysis (as AV products like to do with unknown files), its a standard OS thing. Therefore my rootkit isn't burned either.

discuss

order

No comments yet.