• Home
  • How-To’s
  • OS Directory
  • Reviews
  • About

Os Attack

Subscribe to OS Attack

Windows 7 UAC Security Flaw, Oops!

Posted by Paul Foty in January 30th 2009  

uacsecuredesktop

User Account Control in Windows Vista is very annoying but effective.  It succeeded in making the OS more secure and as much as it has been reviled and trashed it fixed many security problems and drastically reduced Vista’s ability to be infected.  Due to the outcry from aggravated users Microsoft decided to make UAC less annoying by not blacking out the screen and bringing the prompt to the front of other applications when a prompt is needed (for the default level and below).

Microsoft’s intentions were good but as intentions go they can come back to bite you.  Long Zheng and Rafael Ravera have found a huge flaw with this new method of UAC implementation and posted it on iStartedSomething after Microsoft basically told them “it’s too late to fix it”.  Their proof of concept (visual basic script) can easily circumvent UAC, set a startup entry and then reboot the computer.  When the computer is booted up again it is without any UAC.

This type of exploit is extremely easy to implement as they show with their application and would make Windows 7 substantially less secure than Windows Vista.  The fix for Microsoft is a very simple one, always enable “secure desktop”.  This is a policy setting that forces the screen to go black and brings the UAC prompt to the front of all other applications.

Microsoft may not want to take the time to fix this but it is extremely important for Windows 7 to flourish in the marketplace, particularly the enterprise marketplace.  While it is easy enough for an enterprise to simply apply a policy and fix Microsoft’s blunder, security issues don’t make for good publicity.

Check It Out> istartedsomething via CrunchGear

Under: Uncategorized

Tags: Circumvent Security, Malware, Secure Desktop, Security, UAC, Windows 7

Short URL: http://www.osattack.com/BB9

No Comment

SocialTwist Tell-a-Friend

No Comment

Leave Your Comments Below

Please Note: All comments are moderated

To use your own personal Avatar go to http://www.gravatar.com

Random Post

  • Piracy, all software companies deal with it. Some just get creative.
  • Do Cloud Operating Systems deserve to be called "Operating Systems"?
  • Apple is the newcomer to smartphones, NOT Palm
  • Android Vs. Windows CE, another OS death match
  • Bitdefender is now defending Linux
  • Android captured 5% of the mobile OS market in February
  • Is Google Going Too Far?
  • NetBSD 5.0 RC1 Released!
  • Desktop Modifications, Eye candy for those that like it sweet
  • “Windows 7 Not a Game Changer”
Windows 7 Search Sucks! »

OS Attack Categories

  • Apple
  • Cloud Computing
  • Gaming Consoles
  • Linux
  • Malware
  • Netbooks
  • Portable Devices
  • Security
  • Smartphones
  • Tips and Tricks
  • Windows 7
  • Windows PE

Random Recent Posts

  • Backup your data or lose it!
  • Fedora 11 "Leonidas" Has Been Released!
  • Additional Windows 7 applications get un-install options
  • ACCESS Linux Platform releases 3.0, needs a new name
  • Kaspersky Technical Preview for Windows 7
  • At 900 million a year and a new skin is the best that Microsoft can come up with?
  • Computer Hardware Cheat Sheet
  • IBM announces new Cloud service, Lotus Sametime Unyte
  • Palm Pre wins Best In Show at CES
  • Server Upgrade
IE 6 SUCKS! Get a browser that is actually capable of surfing the Internet!

©2008-2009 OS Attack