Part 2 of CrowdStrike’s series examines the security implications of Microsoft’s ClickOnce deployment technology, revealing a previously undocumented attack method involving registry-based COM object hijacking that enables code execution during software installation.