NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Insight into Windows Vista User Account Control

Elevations and ILs don't define a security boundary

By Marius Oiaga, Technology News Editor

15th of February 2007, 16:41 GMT

Adjust text size:


In Windows Vista, the user Account Control is a feature that introduces an alternate privilege model by making all the users, including those in the administrators' group, run with standard user privileges. A requestedExecutionLevel key embedded
in the executable of the applications must require administrative privileges. As a result, the user is presented with a UAC Consent dialog that asks for elevation of privileges.

"Whether you elevate from a standard user account (Over the Shoulder - OTS - elevation) or from an administrative account (Admin Approval Mode - AAM - elevation), you create processes that have administrative rights on the same desktop as those that have standard user rights. Processes elevated from a standard user account run in a different account from those with standard user rights, so the Windows security model defines a wall around the elevated process that prevents the non-elevated processes from writing code into those that are elevated," revealed Mark Russinovich, a Technical Fellow in Microsoft's Platform and Services Division.

In this regard, Windows Integrity mechanism comes on top of the standard Windows security model to prevent input passing from non-elevated processes to elevated processes. Windows Vista attributes an Integrity Level to every process and object. In time, Windows Vista will force all the software developers to build products for users with standard administrative privileges, unlike the current trend in XP.

"Because elevations and ILs don't define a security boundary, potential avenues of attack, regardless of ease or scope, are not security bugs. So if you aren't guaranteed that your elevated processes aren't susceptible to compromise by those running at a lower IL, why did Windows Vista go to the trouble of introducing elevations and ILs? To get us to a world where everyone runs as standard user by default and all software is written with that assumption," Russinovich added.
Read by 1,954 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 11 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Causes Confusion Between "Secure" and "Security"

Microsoft Patches Critical Vulnerability In Windows Vista

Symantec Security for the Impenetrable Vista

Vista Windows.old

Microsoft Is Excluding Users from Vista Security Features

IE7 Security Features Should, In Theory, Protect the Computer?

Is Microsoft Sending the Right Signals for XP Users with Vista?

Microsoft's Insecure Security - the Door for New Exploits

BitDefender Delivers Protection for Windows Vista

38% of Malware Is Vista Compatible

Windows Ultimate Extra DreamScene Available

Download the Windows Vista DVD Covers

Windows Vista - a Sterile Operating System

Windows Vista Kills Networks

Automatic KMS Activation Crack for Windows Vista

Symantec Applauds Its Own Protection for Windows Vista

McAfee Delivers Full Windows Vista Compatibility

Microsoft Takes on the Toughest Job

Windows Vista Home Basic, Home Premium, Business, Enterprise and Ultimate - Comparison

Want Lack of Choice? Buy a Mac

Windows Vista Ultimate KMS & Frankenbuild Crack

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM