Not sure on others but I read the bit before that as contradictory of the bolded bits?
malicious actors with file system access


In a non admin everyone world, gaining 'file system access' with NTFS permission behind the accounts, limits even some to non-read dirs? IE the squirrel folders most refer to.