NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Symantec: Don't Trust Windows Vista UAC Prompts!

Because of the RunLegacyCPLElevated.exe

By Marius Oiaga, Technology News Editor

20th of February 2007, 14:16 GMT

Adjust text size:


Symantec has analyzed the User Account Control in Windows Vista and has presented the verdict. Do not trust UAC prompts. In this regard, Symantec has also provided an example of how
the User Account Control can be abused in order to fool the user in elevating a malicious process. At the basis of this is the fact that the UAC does not provide a security boundary or direct protection, but only a chance for the user to verify an action before allowing it to take place.

"The issue I discovered was that the binary RunLegacyCPLElevated.exe, [which] is designed to provide backward compatibility by allowing legacy Windows Control Panel plug-ins to run with full administrative privileges. What's the drama? I hear you say. The problem stems from the fact that RunLegacyCPLElevated.exe takes as one of its parameters an arbitrary DLL with a particular export. The DLL has to export the CPlApplet function, which is then called with a number of different parameters depending on the action being performed," explained Ollie Whitehouse, Symantec Security Response Researcher.

If you want to find out more about how you can add run levels to legacy control panel applets in Windows Vista via shimming, then click here. But the bottom line is that shimming can also backfire. A malicious piece of code can drop a malformed CPL file onto a disk location where it can write and then call RunLegacyCPLElevated.exe. With the malicious CPL as a parameter, the Vista user will be presented with a UAC prompt that comes from Windows, and not from a third party application. Authorizing such an elevation would give administrative privileges to the malware.

"So while Microsoft may use the word trust when in relation to UAC in some of their documentation with statements such as - "The following illustration details the elevation prompt logic for corresponding levels of trust." - in actual fact, even the data these UAC prompts provide you with can't be trusted," Whitehouse added.
Read by 3,069 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.5/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Vista Windows.old

Is Microsoft Sending the Right Signals for XP Users with Vista?

Microsoft Patches Critical Vulnerability In Windows Vista

Vista vs. XP - Feature Comparison

Windows Vista System Restore

KMS Crack for Vista Home Basic and Home Premium

Windows Ultimate Extra DreamScene Available

Windows Vista Search Kills Google Search

XP Kicks Vista Retail Ass

Windows Vista Causes Confusion Between "Secure" and "Security"

Windows Vista Kills Networks

Get Free Windows Vista RC1

Automatic KMS Activation Crack for Windows Vista

Windows Vista Express-Less Upgrades

Windows Vista Upgrades

Want Lack of Choice? Buy a Mac

Windows Vista Ultimate KMS & Frankenbuild Crack

Disable Command Prompt During Vista Enterprise Installation

Go Beyond Vista - It's Time to Get a Mac

Microsoft Gags the Next Version of Windows

Windows Vista Enterprise Edition Available to All MSDN Subscribers

Microsoft Confirms Vista Follow-Up for 2009

The Best Place to Search for Windows Vista Cracks

Symantec Security for the Impenetrable Vista

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM