Code aims to bypass UAC security in Windows 7

By Tom Espiner, ZDNet UK
Tuesday, February 03, 2009 10:33 AM

A pair of investigators say they have found a way to bypass the User Account Control feature in Microsoft's Windows 7 beta.

User Account Control (UAC) is a Windows security feature, introduced in Vista, that checks whether a user really intends to launch a program or whether malware is at work. It can also be used by companies to restrict user administration rights on a PC.

Graphics student Long Zheng said in a blog post last week that he and developer Rafael Rivera have come up with a method to turn off the feature in the Windows 7 beta.

As UAC in Windows 7 is set by default to 'Notify me only when programs try to make changes to my computer' and 'Don't notify me when I make changes to Windows settings"', Zhong said he asked Rivera to write some code that would emulate a user changing those settings.

Rivera wrote a proof-of-concept program in VBScript that would emulate the keyboard inputs to disable UAC without triggering any Windows alerts. One of the implications of this is that an attacker could automate a restart of an affected PC and add a malicious program with full administrative rights, Zhong wrote in his post last week. The proof-of-concept code is available through a link in that post.

Microsoft had not responded to a request for comment on the issue from ZDNet UK at the time of writing.

However, Zhong later said he had received a response from Microsoft denying that he and Rivera had discovered a flaw. According to Zhong, Microsoft's reasoning was that the malicious code would have to be running on the PC for it to turn UAC off, but the act of implementing that malicious code in the first place would have triggered an UAC alert.

Microsoft has said it put the UAC system of user privileges into Vista in an effort to make it more difficult for users to inadvertently execute malicious programs.

However, the feature was heavily criticized in 2007 by security company Kaspersky, who said that its system of alerts was so annoying that users would switch it off. Microsoft recognized that users could be confused by UAC, and responded in Windows 7 by giving the user greater control over the alert mechanism.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Five tips for tackling a one-time project

Tech Management

Don't let a one-time project derail your career. An IT consultant shares tips on how to successfully manage a "once-in-a-career" event.


Read more »



End of the line for ICT bills

Blog thumbnail

Last Tuesday, I found myself in the Senate to witness the fate of two ICT-related measures – the bill creating the Department of ICT (DICT) and the proposed Cybercrime law..... by Melvin G. Calimag

Read more »

Tags

  1. antivirus
  2. apple ipod
  3. cnet networks inc.
  4. desktop
  5. e - mail
  6. hard drive
  7. intuit inc.
  8. mcafee inc.
  9. microsoft corp.
  10. microsoft windows
  11. microsoft windows vista
  12. microsoft windows xp
  13. norton co.
  14. pc
  15. performance
  16. security
  17. software
  18. tool
  19. web
  20. web site