CMSTPLUA COM UAC bypass spawning hidden elevated PowerShell

Detects the exploitation of the CMSTPLUA COM-object (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7) to bypass User Account Control (UAC). The rule monitors for PowerShell processes instantiating this object, followed by the execution of a hidden-window PowerShell process, bypassing the consent.exe UAC prompt.