An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)
https://mobaxterm.mobatek.net/download-home-edition.html
https://gist.github.com/ahmedsherif/ad56cd3a9ef86cdc05175fb591804c64