By Endri Domi
Overview
This blog post details a logic vulnerability discovered internally in the COM interface exposed from the msi.dll
binary. The vulnerability allows a low-privileged user to cause the MSI service to delete an arbitrary folder that the user has access to, by scheduling its path in the TempPackages
registry key. The service does not validate that the folder being deleted was actu...
