Microsoft confirm, UAC security flaw in Windows 7
D' Technology Weblog —
... To demonstrate how easy it is to automate the disabling of UAC, Rafael wrote a VBScript. An obvious fix for this “issue” would be to force the adjustment of UAC parameters to be confirmed by a human. Until Microsoft addresses this “issue”, you can set UAC to its highest mode to kill any concerns you may have. ...
Microsoft neuters UAC in Windows 7
Hardware 2.0 —
... , we came up with a fully functional proof-of-concept in VBScript (would be just as easy in C++ EXE) to do that - emulate a few keyboard inputs - without prompting UAC. You can download and try it out for yourself here , but bear in mind it actually does disable UAC. Fortunately, there’s a simple workaround: Until when Microsoft decides to fix this, if they do at all, beta users of Windows 7 can also apply a simple fix. Changing the UAC policy to “Always Notify” will force Windows 7 to notify you even if UAC settings change. Annoying, but safe. What’s also annoying is that ...
Windows 7 beta UAC completely vulnerable to malware
TG Daily - All News —
... As a result, using only keystroke commands issued by a malware program, in Windows 7 beta it can activate the UAC, move the slider bar to the "disable messages" position, close the dialog and then proceed through the system doing whatever it wants to in the background without the user ever knowing that their system's been compromised - because they don't see any popups as their UAC setting should've indicated. The discoverer wrote some simple code (which can be downloaded from his page ) and also notes that this is apparently a Microsoft-purposed design feature of Windows 7, ...
Windows 7's UAC is now insecure 'by design'
TechBlog —
... I had to think "bad thoughts" to come up with a way to disable UAC without the user's interaction. The solution was trivial, you could complete the whole process with just keyboard shortcuts so why not make an application that emulates a sequence of keyboard inputs. Zheng and a friend came up with a simple VBScript routine that disables UAC completely. Malicious software could then be installed onto the Windows 7 computer without the user knowing it had been done. You can download it from Rafael Rivera Jr.'s blog . And yes, it really does completely disable the UAC in Windows ...
The oldest trick in the book, literally, defeats UAC in Windows 7
Betanews —
... problems (we should know). So it's to any researcher's credit that a potentially threatening problem be brought into the open prior to Microsoft finalizing the code for everyday use. That said, it's an little embarrassing to discover that a dumbfoundingly simple method for forcing Windows to accept keypresses from a script as though they'd been pressed by a human being, is the focus of a proof-of-concept macro capable of disengaging User Account Control in Windows 7. The macro was published this morning by developer Rafael Rivera , and then kicked into the public spotlight ...
Microsoft agrees to make Windows 7’s UAC more secure
TechBlog —
Ring ring ring ring . . . Mozilla Phone! | Main February 05, 2009 Microsoft agrees to make Windows 7 s UAC more secure win7_3 Never let it be said that Microsoft doesn't listen to its customers. Sometimes, though, those customers have to speak VERY, VERY LOUDLY before the company takes action. Tonight, in an Engineering Window 7 blog post , Microsoft honchos Steve Sinofsky and Jon DeVaan said a security issue pointed out by bloggers Long Zheng and Rafael Rivera will be fixed. As I wrote last week , the issue involves the ability ...




