Uac Vulnerability Found In Windows 7 Beta


Recommended Posts

2 February 2009, 10:03

UAC vulnerability found in Windows 7 Beta

A simple script has been published by developer Rafael Rivera, which uses a vulnerability in the current Windows 7 beta to disable User Account Control (UAC). In a response to complaints about UAC in Windows Vista, Microsoft has made UAC in Windows 7 ask the user for permission less often and even hides prompts when users change Windows settings. Changing the UAC system settings has been made a lot easier for users in the new Windows 7 beta as the default security has been reduced.

Rivera's script sends keyboard commands to the UAC dialog box and re-configures the UAC for a lower security setting, or disables it. The user receives no warning, but is simply asked to restart the PC for the changes to take effect. The script is currently a functional proof of concept.

More at Heise security: http://www.heise-online.co.uk/security/UAC-vulnerability-found-in-Windows-7-Beta--/news/112532

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...