Submit a Story!

Is There an Even Bigger Security Hole in Windows 7's UAC?

 
Earlier this week, our own Josh Kamperschmidt told us how scripts could be used to disable Windows 7's UAC . Well, that's just the prelude to a potentially even bigger security issue: according to Long Zhen of the I Started Something blog, Windows 7's "improved" UAC  can be disabled by malicious software that is coded for auto-elevation . Auto-elevation is a feature that enables software being run by Administrators to skip the annoying "do you want to run this program" prompt that has made Windows Vista's version of UAC one of its most controversial features , not to mention one of the "I'm a Mac" commercials' favorite targets . Unlike the proof-of-concept exploit reported earlier, this one doesn't prompt you to reboot the system: it works silently. So, what is it about Windows 7's UAC that makes it vulnerable? As Zhen puts it: Windows is a platform that welcomes third-party code with open arms. A handful of these Microsoft-signed applications can also ... (link)

Tags:

Related Content
Six editions of Windows 7: better than Vista, still too many
arstechnica.com 2/5/2009 — After a ton of guesswork and rumors flying around, Microsoft has finally confirmed what much of the evidence was pointing to: there will indeed be six editions of Windows 7, just like there were for Windows XP and Windows Vista . ...
Ballmer: Stay on Windows XP and You Will Face a Backlash
pcworld.com 2/6/2009 — Microsoft CEO Steve Ballmer is warning IT organisations that they risk provoking an end user backlash if they don't move off of Windows XP.
Run Windows 7 in VirtualBox
w7forums.com 2/5/2009 — Following on from our article about running Windows 7 within Microsoft Virtual PC, this tutorial will show you how to run Windows 7 by using the more powerful VirtualBox application. VirtualBox is an open-source tool from which you can create a ...
PCGH - Windows Vista versus Windows 7: Graphics cards benchmarks - Windows 7, Windows Vista, Benchmark, graphics cards, driver, review, test
pcgameshardware.com 2/5/2009 — PC Games Hardware checks the 64 bit versions of Windows Vista and the Windows 7 Beta 1 for their gaming performance. Furthermore we wanted to know how well AMD and Nvidia optimized their drivers. For our tests we used the Catalyst 8.12 and the Geforce ...
Microsoft offers to just 'Fix it'
news.cnet.com 2/6/2009 — When people encounter a problem with their PC, they often go to the Web and do a search to see if others have had the problem. If they are lucky, someone has found a fix and listed the steps on either a support document or within a user forum.  ...
Microsoft Changes Windows 7 UAC Due to New Exploit CodePC World Latest Technology News 2/5/2009
A pair of Windows bloggers posted more proof-of-concept code that subverts an important security feature of Windows 7.
Microsoft to Roll Out Two Critical Patches for IE, ExchangePC World Latest Technology News 2/5/2009
Redmond will also issue a patch for SQL Server that it's been working on since last April.
Windows 7 UAC vuln not a vuln, MS repeatsThe Register 2/5/2009
Fixes it anyway When is a Windows 7 vulnerability not a vulnerability? When the malware that's been written to exploit can't be installed without the user's OK.…
Microsoft Smartphone Rumors Gain SteamPC World Latest Technology News 2/6/2009
Microsoft's smartphone launch rumors gain steam again, with an analyst predicting a possible launch in two weeks at the GSMA...
High-slider integrity planned for Windows 7 UACThe Register 2/6/2009
Microsoft spins on flack attack Microsoft has promised changes to a frustrating Windows security feature inside Windows 7, following reported vulnerabilities and an avalanche of criticism.… Free Download - Integrating information across the ...