It is possible to sideload a compromised DLL during the installation at elevated privilege.
Workaround:
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.