Posted by Stefan Kanthak on Sep 07
Hi @ll,
in <http://seclists.org/fulldisclosure/2013/Sep/132> I showed an
elaborated way for privilege elevation using IExpress (and other
self-extracting) installers containing *.MSI or *.MSP which works
“in certain situations”.
Microsoft addressed this vulnerability with
<https://technet.microsoft.com/library/security/ms14-049.aspx>
In <http://seclists.org/fulldisclosure/2013/Oct/5> I showed an
indirect way for…