> Powershell, friend. Changing execution policy requires privileges. Guess what SYSTEM gives you?
PowerShell execution policy is stupid easy to bypass. You simply pass the '–ExecutionPolicy Bypass' parameter when launching the script. Of course, since you already have complete control of the user account, being able to run PowerShell isn't nearly as big a deal as the fact that you can run anything at all.
> Plus you can disable windows defender and install any nasty things you want!
Windows defender, like pretty much all AV software, is crap anyways and won't detect most of the things you'd be interested in doing. It's a low-effort screen for well known malware. Case in point: it didn't catch your malicious installer when Steam downloaded and ran it in this scenario did it?
> Pretty sure you’d need system to snoop/inject traffic too.
That may well be true, but considering I pretty much already have full control of the user account and can therefore do everything it can do on the network without injecting anything, I'm not sure what is gained.
> No fucking shit, but you don’t let them walk into system just because they got user.
Eh, it isn't really worth my effort to try and prevent it when all they'll have to do is fire a UAC prompt the user will almost certainly just click through anyway. Especially considering what little (basically nothing) it gets the attacker.
> Because they don’t know Steam is insecure by design! They trust Steam! That’s the problem! This isn’t common knowledge and since Steam won’t fix it, it needs to become common knowledge.
So here's the scenario you're talking about: A user has installed Steam on their work computer. They use Steam to download an installer that is actually malicious and this fact has not been caught by Valve yet. Steam, who's entire purpose is to install games, runs the installer. Consequently, the user account is now owned by an attacker.
...And even if this vulnerability were patched ALL OF THE ABOVE WOULD STILL BE TRUE!