well first off i know that the full screen mode will not allow the full keybooard use for just this reason. that is really what stops this from working.
but just say that the black hat could enable full keybaord and mouse in full screen.
here is the case:
joe opens ie maximized to fill the desktop.
so his display is the start menu the task bar and IE.
now he goes to some site that has evil-silverlight-app and it does a fullscreen mode in a way that he does not realize what happened.
the sl app can find out what version of winbdows and ie via html bridge and javascript.
based on that it can load a style / skin to mimic the same.
now just have a list of say the top 10 banks and e-commerce domain names and store a set of templates on evil server for them.
user enters www.mybank.com and gets a skin that looks like his bank and he tries to login.
depending on how far the evil guy wants to go that might be all he needs....
if the list had say paypal , amazon , several banks ..... simulate some http errors and let him login a few times to different sites then exit the app...
user might not even realize what happened.
or figures his browser crashed and re-start windows.
but the black hat may now have some high value bank logins and cc #'s and his home address and whatever eles was entered.
right now as far as i know the current fullscreen mode locks out keyboard inputs in a way that stops this.
and this is why, cuase if full key and mouse worked with full screen this could be done.