Windows 7 UAC Feature Still Vulnerable

raj11650

New member
Pro User
VIP
Local time
5:37 PM
Messages
851
Location
India ,Chennai
The Microsoft blogger who first called attention to a security vulnerability in Windows 7's User Account Control (UAC) feature claims it still exists and that Microsoft won't fix it, even as the company nears final code completion on the OS.

Long Zheng, who writes the popular "I Started Something" blog, has posted a video online showing how UAC, a security feature first introduced in Windows Vista that sets user privileges on a PC in Windows 7, can be exploited.

Zheng also pointed to an instructional document by Microsoft Technical Fellow Mark Russinovich that attempts to explain UAC, saying it clearly states that Microsoft has no intention of fixing a change it made in the UAC in Windows 7 that leaves the new OS less secure because it allows someone to remotely turn the feature off without the user knowing.

Zheng first pointed out this change and its vulnerability back in February. At the time he said that the new UAC "standard user" default setting, which does not notify a user when changes are made to Windows settings, is where the security risk lies. A change to UAC is seen as a change to a Windows setting, so a user will not be notified if UAC is disabled, which Zheng said he was able to do remotely with some keyboard shortcuts and code.
Read more

[digg]http://www.sevenforums.com/news/13614-windows-7-uac-feature-still-vulnerable.html[/digg]
 

My Computer

Computer Manufacturer/Model Number
Custom Build
OS
win 7 build 7600.16385 x64
CPU
AMD Athlon Dual core 7750 2.7GHz
Motherboard
Gigabyte GA78MA s2h
Memory
4GB 800Mhz
Graphics Card(s)
ATI HD 3200 IGP
Monitor(s) Displays
Acer 15 inch
Screen Resolution
1280x720
Hard Drives
Seagate 1 TB
Keyboard
Logitech
Mouse
Logitech
Internet Speed
Airtel DSL 2Mbps
basically I am guessing if they made the change he wants then when toggling the setting you would get a UAC prompt, a small price to pay to fix the exploit I guess.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers
so.... is it safe or not?
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
Windows 7 x64
CPU
Intel Core 2 Duo E6750
Motherboard
Gigabyte GA-P35-DS3-L V2.0
Memory
4GB G.Skill PC2-8500
Graphics Card(s)
eVGA GTX 460
Sound Card
Auzentech X-Fi Prelude 7.1
Monitor(s) Displays
Envision 2219S-1 (22")
Screen Resolution
1680x1050
Hard Drives
Samsung 750GB [SATA 2] //
Seagate FreeAgent Go 500GB
PSU
Corsair CX400
Case
Raidmax Sagitta
Cooling
Stock
Keyboard
HP Wireless Elite
Mouse
Logitech G7 Gaming Mouse
Internet Speed
1Mbit
Other Info
*Gaming Input: xBox 360 Controller + Logitech Rumblepad 2 Cordless
*Speakers: Logitech Z5500
*Headphones: Sennheiser HD555
I disable it myself anyway.
 

My Computer

Computer Manufacturer/Model Number
MasterB/Custom
OS
Windows 7 Professional x64
CPU
QuadCore AMD Phenom II X4 Black Edition 955 3.2 GHz
Motherboard
Asus M4A785TD-V Evo
Memory
8 GB Crucial DDR3
Graphics Card(s)
SAPPHIRE Radeon HD 4890 1GB HDMI New Edition
Sound Card
VIA VT1708S HD Audio 7.1 onboard/ ATI HDMI video card
Monitor(s) Displays
Acer H233H 23'' LCD HDMI
Screen Resolution
1920x1080
Hard Drives
1x 500GB and 1x 1TB 7200RPM 32MB Cache WD Caviar Black
PSU
CORSAIR CMPSU-620HX 620W
Case
COOLER MASTER Storm Scout SGC-2000
Cooling
2x 140mm and 1x 120mm case fans, Stock CPU fan
Keyboard
Logitech MX 3200
Mouse
Logitech MX 3200
Internet Speed
15 Mbps
Other Info
My first build!
I wouldn't like that approach, but if it's not working as it should, then why keeping it on? Pitty, now when I got pretty much used to it.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
Windows 7 x64
CPU
Intel Core 2 Duo E6750
Motherboard
Gigabyte GA-P35-DS3-L V2.0
Memory
4GB G.Skill PC2-8500
Graphics Card(s)
eVGA GTX 460
Sound Card
Auzentech X-Fi Prelude 7.1
Monitor(s) Displays
Envision 2219S-1 (22")
Screen Resolution
1680x1050
Hard Drives
Samsung 750GB [SATA 2] //
Seagate FreeAgent Go 500GB
PSU
Corsair CX400
Case
Raidmax Sagitta
Cooling
Stock
Keyboard
HP Wireless Elite
Mouse
Logitech G7 Gaming Mouse
Internet Speed
1Mbit
Other Info
*Gaming Input: xBox 360 Controller + Logitech Rumblepad 2 Cordless
*Speakers: Logitech Z5500
*Headphones: Sennheiser HD555
Please keep in mind, this is a Bootkit exploit: Someone has to physically sit down at your computer and use corrupted media to boot the system. It cannot be downloaded, eMailed as an attachment, clickstreamed, hidden in a file for later execution, or any of the other ways people try to hack into your computer.

Also - Keep in mind this is the same way into a computer that technicians use to wipe a forgotten password.


Quite frankly, I'm having a hard time understanding why people appear to have so much sand in their vaginas over this. If Someone Has Physical Access To Your Computer, Then What's Preventing Them From Simply Stealing The Hard Drive? Or Stealing The Whole Thing Outright?
 

My Computer

Computer Manufacturer/Model Number
Home Built
OS
Windows 7 (x64)
CPU
Intel Core i7 960 @ 3.8GHz (3.2GHz stock)
Motherboard
EVGA E758 X-58
Memory
6GB OCZ DDR3 1600
Graphics Card(s)
Powercolor AX5870 (ATI 5870 w/improved cooling)
Sound Card
Omega Claro+
Monitor(s) Displays
1. Acer P243W (24") 2. Samsung T260 HD HDMI HDTV/Monitor
Screen Resolution
1920 x 1200 x 2
Hard Drives
(1) 128GB Kingston SNVP325-S2 SSD for OS/Games
(2) 500GB WD Caviar Black - Storage
PSU
Corsair CMPSU-850HX
Case
Lian Li PC-K60WB
Cooling
Thermalright Venemous-X
Keyboard
Microsoft Natural keyboard 4000
Mouse
Microsoft Sidewinder
Internet Speed
Cable
Other Info
165 bclk, 23 Multi
Looks like some of us will need to go back to using an Antivirus program full-time once again :mad:

Im guessing the decision not to fix UAC is a direct result of people like myself who have very good experience using computers who do not use an Antivirus, I can identify trojens and virus's before they are executed and have been able to run without an Antivirus for two years now without a single infection while downloading at least 80gb of data a month (least I do :p) Ive tested my system each time a new AV product version has been released and have not found one infection in two years and I can thank UAC for giving Power Users the ability to dump their AV permanently like myself and others have.

Why change a perfectly good security model just for (noobs!) one that completely defeats the purpose of putting it into the system in the first place? Its not like users cant find and change UAC settings :mad: If its not fixed then It should just be removed because no one will continue using it, especially if it doesn't offer the security it once did and what people have come to expect.

Microsoft seriously needs to prevent any automated tampering of UAC controls by applications otherwise its not worth anyone ever using and as it stands right now, UAC is dead weight and offers users nothing for the annoyance it causes. I will disable it on all machines I build and sell in the future and advise customers it offers them zero protection :cry:
 
UAC is useless? HA! i knew that when i first used vista. i thought to myself, "you gotta be f%*kin' kiddin' me." now it serves as nothing more that a placebo, i think if you have a firewall, a decent AV, and anti-spyware, you'll be fine. UAC is just another annoying "feature" MS throws in there, to herd sheepish consumers (no offense folks).

XP didnt have it, and I've only gotten a few viruses, but that was due to my own stupidity. Most of which were catastrophic...like i said... my bad :D
 

My Computer

Computer Manufacturer/Model Number
eMachines W3502
OS
Windows 7 Ultimate x32
CPU
Intel Celeron D 3.2 Ghz 533 fsb (LGA 775)
Motherboard
Intel D101GGC
Memory
1 GB (2x512MB) PC-3200 DDR @ 200Mhz
Graphics Card(s)
Nvidia GeForce 9400GT- 1GB
Sound Card
Sound Blaster X-Fi Xtreame Gamer
Monitor(s) Displays
19" LCD HDtv
Screen Resolution
1360x768 @ 60Htz
Hard Drives
SeaGate Barracuda 750GB
SeaGate Barracuda 100GB
Toshiba CD/DVDW/ TS-H552D [DVD+R, DL]
PSU
stock (idk)
Case
The busted remains of the stock case
Cooling
Dust cooled, waitwut?
Keyboard
Stock. Missing a few keys.
Mouse
Logitech LX8 5-btn mouse (wireless)
Internet Speed
TWC 10Mb
Other Info
Keeps going, and going, and going.......
I think that UAC was created to prevent unauthorized changes to your computer. If someone can turn it off without being authorized to do so, than that's just plain ironic, as well as useless.

For years, Windows has been the choice of computer compainies around the world. Since the 90's, UAC didn't exist, and people didn't have many problems. I think UAC is overrated, but it can be handy when you go to one of those websites that you just can't trust.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5610
OS
Windows 7 Professional, Windows Longhorn 4074
CPU
Intel Centrino Duo T2350 @ 1.87 GHz
Motherboard
Acer Grapevine
Memory
1GB (2x 512MB DDR2 400Mz)
Graphics Card(s)
Intel Integrated 945GM Chipset
Sound Card
On-Board RealTek HD Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1280x800
Hard Drives
160GB SATA HD
PSU
Generic PSU
Case
Acer Aspire 5610 Standard Case (U.S. Version)
Cooling
Air
Keyboard
Built-In / Random Logitech wireless keyboard
Mouse
Synaptics Touchpad / Logitech Click! optical mouse.
Internet Speed
2.57 Mbps Download / 0.29 Mbps Upload / 57ms Ping
Other Info
I call it the craptop.
UAC is a royal pain, it simply gets in the way. At least the screen does not flicker away as it did in vista ....
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Build 7229 64bit + Vista ultimate 64 bit
CPU
Intel core two Quad CPU Q9550 @ 2.83HHz
Motherboard
Gigabyte GA-EP45-DS3R
Memory
8 GB corsair dominator 2GB x 4
Graphics Card(s)
Asus Passive cooled Nvidia 8600GTS
Monitor(s) Displays
Dell 24 inch
Screen Resolution
1920 x 1200
Hard Drives
western Digital velociraptor 74GB
750gb samsung
PSU
corsair 450 watt
Case
Coolermaster wavemaster (customised mainly to be cool/quiet)
Cooling
stock
Keyboard
Logitech wavemaster
Mouse
Logitech wavemaster
Internet Speed
24mb
I think you'll find the default seting for UAC on 7 is the same as in Vista.

That is not susceptible to this type of exploit.

It is only if you turn it down ( no darkened desktop) that it becomes less secure - obviously.

MS are simply giving people the choice.
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
You see, I thought that the defualt setting was that one level lower than the Vista UAC setting.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5610
OS
Windows 7 Professional, Windows Longhorn 4074
CPU
Intel Centrino Duo T2350 @ 1.87 GHz
Motherboard
Acer Grapevine
Memory
1GB (2x 512MB DDR2 400Mz)
Graphics Card(s)
Intel Integrated 945GM Chipset
Sound Card
On-Board RealTek HD Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1280x800
Hard Drives
160GB SATA HD
PSU
Generic PSU
Case
Acer Aspire 5610 Standard Case (U.S. Version)
Cooling
Air
Keyboard
Built-In / Random Logitech wireless keyboard
Mouse
Synaptics Touchpad / Logitech Click! optical mouse.
Internet Speed
2.57 Mbps Download / 0.29 Mbps Upload / 57ms Ping
Other Info
I call it the craptop.
They have reduced the number of prompts required in some multi prompt scenarios involving Windows applications.

The behaviour for non-Windows elevations is the same as it was for Windows Vista.
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
I think you'll find the default seting for UAC on 7 is the same as in Vista.

That is not susceptible to this type of exploit.

It is only if you turn it down ( no darkened desktop) that it becomes less secure - obviously.

MS are simply giving people the choice.

The default Vista setting is High, Windows 7 uses one down that permits the majority of Microsoft's software to run without prompting. You can also turn off ScreenDarkening without affecting any other UAC policy via the Local Security Policy settings ;)

They have reduced the number of prompts required in some multi prompt scenarios involving Windows applications.

The behaviour for non-Windows elevations is the same as it was for Windows Vista.

Unfortunately no, Microsoft are able to reduce the amount of prompts by checking executables for a specific Microsoft signature and auto-elevating any signed executable that matches that singature.

UAC is completely different from Vista's UAC, A non-Windows application can gain Administrative permissions without a single prompt with Windows 7's default configuration, hence why these changes have become a big issue, on Vista it cant be done.

Microsoft have always said UAC is not a security feature, It used to be on Vista but its not on Windows 7. It will not prevent an application from gaining administrative permissions even if you deny consent to the elevation.
 
Thanks dmex,

I was quoting from Mark Russinovich

we reduced the number of prompts in several multi-prompt scenarios (for example, installing an ActiveX control in IE )

He did also say this :

we further refactored the system such that someone with standard user rights can execute more tasks.

The reason that elevation of (most) Windows executables in the two middle settings doesn't result in a prompt is that the system "auto elevates" Windows executables... it must be digitally signed by the Windows publisher, which is the certificate used to sign all code included with Windows (it's not sufficient to be signed by Microsoft, so Microsoft software that's not shipped in Windows isn't included); and it must be located in one of a handful of "secure" directories. A secure directory is one that standard users can't modify

and this:

The behaviour for non-Windows elevations is the same as it was for Windows Vista...From the perspective of malware, Windows 7's default mode is no more or less secure than the Always Notify mode ("Vista mode")

So it is the middle one that might be problematic, I suppose.

He might be trying to downplay the risk.;)
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
I disabled UAC anyways. Plus barely anyone would want access to my **** computer in the first place lol.
 

My Computer

Computer Manufacturer/Model Number
Dell Laptop Studio 1537
OS
Windows 7 x64 7229
CPU
Intel Core 2 Duo CPU T6400
Memory
4 GB
Graphics Card(s)
Mobile Intel 45 Chipset
I disabled UAC anyways. Plus barely anyone would want access to my **** computer in the first place lol.

eeh..heerm
see my specs .... :D
im hoping some hacker will feel bad for me and use my credit card to buy me a new computer.
 

My Computer

Computer Manufacturer/Model Number
eMachines W3502
OS
Windows 7 Ultimate x32
CPU
Intel Celeron D 3.2 Ghz 533 fsb (LGA 775)
Motherboard
Intel D101GGC
Memory
1 GB (2x512MB) PC-3200 DDR @ 200Mhz
Graphics Card(s)
Nvidia GeForce 9400GT- 1GB
Sound Card
Sound Blaster X-Fi Xtreame Gamer
Monitor(s) Displays
19" LCD HDtv
Screen Resolution
1360x768 @ 60Htz
Hard Drives
SeaGate Barracuda 750GB
SeaGate Barracuda 100GB
Toshiba CD/DVDW/ TS-H552D [DVD+R, DL]
PSU
stock (idk)
Case
The busted remains of the stock case
Cooling
Dust cooled, waitwut?
Keyboard
Stock. Missing a few keys.
Mouse
Logitech LX8 5-btn mouse (wireless)
Internet Speed
TWC 10Mb
Other Info
Keeps going, and going, and going.......
eeh..heerm
see my specs .... :D
im hoping some hacker will feel bad for me and use my credit card to buy me a new computer.
Haha I have an eMachines T2682 and a T2893 right next to me, from like 2006.
 

My Computer

Computer Manufacturer/Model Number
Dell Laptop Studio 1537
OS
Windows 7 x64 7229
CPU
Intel Core 2 Duo CPU T6400
Memory
4 GB
Graphics Card(s)
Mobile Intel 45 Chipset
Haha I have an eMachines T2682 and a T2893 right next to me, from like 2006.

MFC date on my MoBo is 2004, down right dinosauric for technology standards
 

My Computer

Computer Manufacturer/Model Number
eMachines W3502
OS
Windows 7 Ultimate x32
CPU
Intel Celeron D 3.2 Ghz 533 fsb (LGA 775)
Motherboard
Intel D101GGC
Memory
1 GB (2x512MB) PC-3200 DDR @ 200Mhz
Graphics Card(s)
Nvidia GeForce 9400GT- 1GB
Sound Card
Sound Blaster X-Fi Xtreame Gamer
Monitor(s) Displays
19" LCD HDtv
Screen Resolution
1360x768 @ 60Htz
Hard Drives
SeaGate Barracuda 750GB
SeaGate Barracuda 100GB
Toshiba CD/DVDW/ TS-H552D [DVD+R, DL]
PSU
stock (idk)
Case
The busted remains of the stock case
Cooling
Dust cooled, waitwut?
Keyboard
Stock. Missing a few keys.
Mouse
Logitech LX8 5-btn mouse (wireless)
Internet Speed
TWC 10Mb
Other Info
Keeps going, and going, and going.......
I have a desktop with a 2002 MFC date :)
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5610
OS
Windows 7 Professional, Windows Longhorn 4074
CPU
Intel Centrino Duo T2350 @ 1.87 GHz
Motherboard
Acer Grapevine
Memory
1GB (2x 512MB DDR2 400Mz)
Graphics Card(s)
Intel Integrated 945GM Chipset
Sound Card
On-Board RealTek HD Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1280x800
Hard Drives
160GB SATA HD
PSU
Generic PSU
Case
Acer Aspire 5610 Standard Case (U.S. Version)
Cooling
Air
Keyboard
Built-In / Random Logitech wireless keyboard
Mouse
Synaptics Touchpad / Logitech Click! optical mouse.
Internet Speed
2.57 Mbps Download / 0.29 Mbps Upload / 57ms Ping
Other Info
I call it the craptop.
Back
Top