5 ms·
The thing about c:\windows\temp is you can’t modify another user’s files but you can create your own. It’s actually a _really_ common vector to exploit poorly
by logbiscuitswave 4y ago
The thing about c:\windows\temp is you can’t modify another user’s files but you can create your own.
It’s actually a _really_ common vector to exploit poorly written installers by dropping your own file (like a malicious dll or exe) into that directory as a low rights user in the hope that the high rights installer process will then load that code. That’s presumably what’s happening in this case.