KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows 7 RTM 7600.16385.090713-1255 HERE !

How to activate Windows 7 RC build 7600, 7264, 7231 and olders


Windows 7 UAC has a second flaw

section: windows, for your questions: KezNews forum, 4.2.2009

    Tip: Click here to update all your PC's outdated drivers

Long Zheng of I Started Something has uncovered a flaw in Windows 7's UAC that means malware can elevate itself to administrator privileges.




This news comes after a previously discovered flaw in Windows 7's new tiered UAC system that meant malware can disable UAC silently.

Zheng has stated "a second UAC security flaw in the Windows 7 beta's default security configuration allows a malicious application to autonomously elevate themselves to full administrative privileges without UAC prompts or turning UAC off", which is bad news for Microsoft. It is also bad news for all the people currently running the Windows 7 beta, leaving them with a security risk. Zheng recommends that, if you're using Windows 7 currently, set your UAC to High to reduce any potential problems. For more information on how to set the UAC level please read our UAC overview.

Windows 7 has the ability to allow Microsoft-signed applications to become 'trusted' by UAC, reducing the number of UAC prompts. However, certain Microsoft applications can execute third-party code, which, while being for legitimate reasons, can be exploited for malicious purposes. This can fool the average consumer, as they would (correctly) assume Microsoft products are safe, and that then has a flow-on effect, leaving them assuming that any code run within Microsoft products is also safe.

Microsoft has not commented on this latest flaw but last week Microsoft denied the original flaw was not a risk. Rumors are that it will be addressed internally and Microsoft will be making a statement regarding these issues.

For more information on this risk, and a non-malicious file to try this flaw for yourself, head over to Within Windows to check it out.

source: neowin.net

  >> Click Here to Run a Free Scan for PC Errors <<

send email Send link 2 friend  |  Permalink
<< previouse article
Windows 7 Wins on Netbook PCs
next article >>
Microsoft: Windows XP to Windows 7 upgrade possible

MORE RELATED ARTICLES:
Microsoft backpedals on UAC flaw || Replace Windows Vista UAC with Smart UAC Replacement || Microsoft neuters UAC in Windows 7 || Microsoft: Update on Windows 7 UAC issues || Flaw in Windows 7 and Vista could allow remote reboot

Comments(3)

Is microsoft tarded?

By Guy on 05.02.2009 - 00:02
so microsoft came up with uac, the most annoying thing in windows, for security reasons. yet, the thing its supposed to be stopping has a way around it? uac should just be removed all together then.

Time to dump UAC!!!!

By The CAT on 05.02.2009 - 22:02
lets face it, it's an annoyance and not a security feature. while i appreciate trying to enhance security, the goal of that ideal is to provide it transparently, which uac doesn't!!!

indeed.

By zm on 15.02.2009 - 06:02
i turned this shit off ever since i started using vista.

i mean what's the point?


No new comments are allowed for this article.

For your questions use our KezNews Forum