So yes, if the program didn't exist at all, there would be no way to uninstall it in an unauthorized manor. So the vulnerability wouldn't exist. You wouldn't necessarily be any more secure though.
If you have 10 layers of security and 5 have holes in them, you have 5 vulnerabilities, but you're reasonably secure. If you have 0 layers of security and thus 0 holes in them, you might arguably say you have 0 vulnerabilities, but you would be less secure than the 5 vulnerability system. In the early days of computing you would log in with your username only, no password. Their threat model didn't consider intentional attacks, thus there were no vulnerabilities, but anyone could use anyone else's account.
>Uninstall protection prevents unauthorized users from uninstalling the Falcon Agent
>The “Maintenance Manager” role is available which grants permission to access the maintenance tokens. This role must be enabled against the Falcon user’s account in order to obtain maintenance tokens or manage policy related to Uninstall Protection.
Putting those 2 sentences together seems to lead to the conclusion that if someone doesn't have the "Maintenance Manager" role, that person will be prevented from uninstalling the Falcon Agent. It's unclear to me if all admin users are considered to have the Maintenance Manager role.
https://www.crowdstrike.com/blog/tech-center/uninstall-prote...
One example I know off the top of my head because I know from experience is accessing Bluetooth encryption keys in the registry. Even if you launched Regedit as Administrator, you'll get ACCESS DENIED reading them. But if you use `psexec` to start Regedit as the SYSTEM user, you'll have access.
My guess is that CrowdStrike installs itself with permissions that prevent Administrator from uninstalling it.