http://www.istartedsomething.com/20...rosoft-wont-fix-code-injection-vulnerability/
http://www.istartedsomething.com/20...ty-video-demonstration-source-code-released/\
Wow, I'm going to make sure my settings are raised to "always notify."I wonder why this hasn't been fixed yet....
-
It hasn't been fixed because Microsoft is in a no-win situation here. There are two courses of action:
1) Microsoft continues with the current behaviour of UAC in Win7, opening a (supposed) security vulnerability but with fewer prompts
2) Microsoft reverts back to Vista UAC behaviour, which creates UAC prompts for everything.
Neither solution is very good. Microsoft caught a lot of flak from consumers about UAC in Vista, which is why they strove to fix the problem in 7. But at the same time, UAC was never really intended to be a complete security barrier - a well-written piece of malware could get past UAC even on Vista because UAC wasn't designed to prevent elevation of malware.
Although despite this, I'm personally disappointed in Microsoft's choice in Windows 7. UAC may be annoying, but automatic elevation kinda defeats the purpose of UAC entirely.
New UAC issue?!
Discussion in 'Windows OS and Software' started by booboo12, Jun 12, 2009.