You would probably have to exploit the fact that Windows allows a user to modify a process of which they are the owner - perhaps execute it in the memory space of explorer.exe (though I'm not sure if this is run with Admin privs on vista or not - the more I think about it, it probably isn't, or nothing else under it would need to ask for admin privs). But you get the idea - do a bit of research on it
~phoenix910




