NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Vista's UAC Issues Extend to Security Policies

Reveals Symantec

By Marius Oiaga, Technology News Editor

21st of February 2007, 10:19 GMT

Adjust text size:


Symantec has decided to intervene in the face-off between Joanna Rustkowska and Mark Russinovich over the User Account Control in Windows Vista. In this context, Ollie Whitehouse, Symantec
Security Response Researcher has taken Rustkowska's side and claimed that the User Account Control can be easily circumvented in order for malicious code to gain administrative privileges.

Microsoft's position on the matter is that UAC does not build security boundaries, and that its role is to offer users a chance to verify an application before running it with elevated privileges. Additionally, Russinovich claims that implementation bugs in User Account Control are not security bugs.

The bottom line is that although User Account Control has been applauded as one of the top additions to the Windows Vista security, because of the fact that it does not provide security boundaries, a malicious process running restricted can elevate itself to administrative rights once the user launches a legitimate process with elevated privileges.

Additionally, a malformed CPL file can hijack the RunLegacyCPLElevated.exe in order to fool the user that a request for administrative right comes directly from Windows Vista and not from malicious code. Via RunLegacyCPLElevated.exe users are able to add run levels and especially administrative privileges to legacy Windows Control Panel plug-ins.

"Unfortunately, this particular issue I discovered also has an unintended consequence on a security policy which may be used by enterprises. There is a security policy item called "User Account Control: Only elevate executables that are signed and validated," which is designed to ensure that only trusted code can be elevated. Well, unfortunately due to the same reasons the UAC prompt can be fooled, this security policy can as well," Whitehouse revealed.
Read by 1,114 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Automatically Deny Elevation Requests in Windows Vista

Windows Vista Security Model - A Big Joke

Windows Vista UAC Implementation Vulnerability

Symantec: Don't Trust Windows Vista UAC Prompts!

Windows Vista UAC Triggers

Windows Vista UAC Colors

Microsoft Security Is a Conflict of Interest

Microsoft Relaxed User Account Control

Windows Vista - a Sterile Operating System

Vista's UAC a Trade Off Between Security and Usability

Apple Recommends That Customers Wait to Upgrade to Windows Vista

Symantec Applauds Its Own Protection for Windows Vista

38% of Malware Is Vista Compatible

Vista Speech Recognition Vulnerability - Video Demonstration

Admin Approval Mode in Windows Vista

Setting Up for Windows Vista Benchmarking

The Correct Way to Install Windows Vista - Video Tutorial

Windows Chief to Retire Following Vista's Release

The $500 Million Windows Vista "Wow"

The Quasi Immaculate Windows Vista

Windows Vista Application Compatibility Toolkit 5.0 Available

Insight into Windows Vista User Account Control

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM