Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.
runexehelper.exe c:\windows\system32\calc.exe
Usecase: Executes arbitrary code
Privileges required: User
OS: Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022
MITRE ATT&CK®: T1218