Skip to main content

Windows 7 Security Hole

Security researcher Long Zheng has posted notification (along with a proof of concept) of an issue in the beta version of Windows 7. He’s shown how an attacker could bypass the User Account Control (UAC), although he’s also shown how it can be remedied quite simply.

The UAC has been a bane of Vista users, as it notifies the user every time a program tries to alter the system. Many have disabled UAC because of its frequent dialog boxes. In Windows 7, though, Microsoft has granted new rules that allow changes to Windows settings without notification, although other alterations still requite notifying the user.

But, as Zheng pointed out:

“The Achilles’ heel of this system is that changing UAC is also considered a ‘change to Windows settings’, coupled with the new default UAC security level, would not prompt you if changed. Even to disable UAC entirely.”

“We soon realized the implications are even worse than originally thought. You could automate a restart after UAC has been changed, add a program to the user’s startup folder and because UAC is now off, run with full administrative privileges ready to wreak havoc.”

He noted that Microsoft could implement a fix “without sacrificing any of the benefits the new UAC model provides, and that is to force a UAC prompt in Secure Desktop mode whenever UAC is changed, regardless of its current state. This is not a fool-proof solution (users can still inadvertently click ‘yes’) but a simple one I would encourage Microsoft to implement seeing how they’re on a tight deadline to ship this.”

Zheng said he has informed Microsoft of the problem, but the company has insisted that “the functionality is ‘by design’, dismisses the security concerns and again leans towards they will not be addressing the issue for the final release of Windows 7.”

Editors' Recommendations

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
A massive Windows 11 AI feature may launch next week despite privacy concerns
Privacy settings in Windows 11.

Windows 11 continues to build a large toolset of AI features, but the one rumored to soon launch may be the biggest change yet -- especially when it comes to your PC's privacy. Windows Latest reports that in Build 26212, the Windows 11 AI integration is named Recall and can be found on the Privacy & Security page in settings (via Albacore on X).

The concern is due to its privacy toggle. According to the latest build, you can record everything on your screen to help you better find something you were working on or searching for. The positive side is that it can help you find the report you edited when you can't remember where you saved it by accessing the timeline interface. It will also help users with their browsing history. For example, if you searched for how to use WhatsApp Web, but can't remember which browser you used or what site the information was on, AI Explorer (or Recall, as it may be named) can find the information for you.

Read more
How to find your Windows 11 product key
EcoFlow River 2 Pro used indoors to power office computer and equipment.

Your Windows 11 product key is about as important as your social security number. Well, at least as far as your PC’s operating system goes. This is a random combination of numbers, letters, and dashes that you’ll seldom need, but when you do, you’re going to need to know where to find it. For Windows 11 users, there are multiple ways to access this crucial code, but we highly recommend writing it down and storing it in a safe place, too.

Read more
You can play almost any Windows game on Mac — here’s how
How to play Fortnite on Mac

Want to play games on your Mac? It's easier than you might think. In fact, it's not too complicated to play just about any game on Mac. Bugs, performance issues, and compatibility issues aren't non-existent, and it takes a few more hoops to jump through, but if you're a dedicated Mac gamer, we know you won't mind.

Read more