Security experts Florian Bogner devised a method dubbed AVGater to escalate privileges by abusing the quarantine feature of some antiviruses. The attack chain starts by inducting AV software into placing a malicious DLL file into quarantine. The attacker then uses the security applications Windows process, that runs with SYSTEM permissions, to restore the file. The malicious file is not restored to its original location, but to a different folder from which it is possible to execute a privileged process such as the Program Files or Windows folders.”]
Source: https://securityaffairs.co/wordpress/65405/hacking/avgater-attack-antivirus.html