There are a lot of issues here, but isn't a glaring one the fact that any random file browser window lets you get a shell? Shouldn't this be something for the developer to disable for their particular program if their use case of browsing to choose an install folder in no means requires it? Do the Microsoft APIs even allow for this kind of configuration?
Given they already have admin rights it's basically game over, but not having the option to open a shell would have still reduced the attack surface and required a "real" exploit to do so.