Skip to main content

Windows 7 Security Hole

Security researcher Long Zheng has posted notification (along with a proof of concept) of an issue in the beta version of Windows 7. He’s shown how an attacker could bypass the User Account Control (UAC), although he’s also shown how it can be remedied quite simply.

The UAC has been a bane of Vista users, as it notifies the user every time a program tries to alter the system. Many have disabled UAC because of its frequent dialog boxes. In Windows 7, though, Microsoft has granted new rules that allow changes to Windows settings without notification, although other alterations still requite notifying the user.

But, as Zheng pointed out:

Recommended Videos

“The Achilles’ heel of this system is that changing UAC is also considered a ‘change to Windows settings’, coupled with the new default UAC security level, would not prompt you if changed. Even to disable UAC entirely.”

“We soon realized the implications are even worse than originally thought. You could automate a restart after UAC has been changed, add a program to the user’s startup folder and because UAC is now off, run with full administrative privileges ready to wreak havoc.”

He noted that Microsoft could implement a fix “without sacrificing any of the benefits the new UAC model provides, and that is to force a UAC prompt in Secure Desktop mode whenever UAC is changed, regardless of its current state. This is not a fool-proof solution (users can still inadvertently click ‘yes’) but a simple one I would encourage Microsoft to implement seeing how they’re on a tight deadline to ship this.”

Zheng said he has informed Microsoft of the problem, but the company has insisted that “the functionality is ‘by design’, dismisses the security concerns and again leans towards they will not be addressing the issue for the final release of Windows 7.”

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
Upgrade to Windows 11 Pro and enhance your PC experience
windows 11 pro deal retailking december 2024 upgrade to and reimagine promo  edited

TL;DR: Get Windows 11 Pro for $17.97 until December 22 and enjoy premium features for work and play.

Microsoft Windows 11 Pro is the upgrade that takes your PC to the next level. With an intuitive design, enhanced multitasking tools, and robust security features, it’s built to streamline your workday and elevate your entertainment experience — with a lifetime license on sale for just $18 through December 22.

Read more
7 surprising things you didn’t know you could do with AI
robot and human hands touching fingertips

When most people think of generative AI, their thoughts immediately jump to popular AI chatbots like ChatGPT, Gemini, and Copilot — all of which do basically the same sorts of generative things, just wearing different hats.

In reality, AI is capable of so much more than simply regurgitating text, images, and computer code. A new surge of AI tools is enabling all sorts of things you may not have thought possible before. This list could be much longer, but to give you a taste of how broad AI is reaching, here are seven surprising tasks that generative AI can help you accomplish.
Build an online brand

Read more
I’m running out of reasons not to ditch Windows for good
The M4 Mac mini with a display in the background.

As of now, I spend my time split between a Windows PC and a MacBook Pro. Both serve their purpose to my needs, and as much as I'd like to unify everything into one device, I haven't found a single machine that could truly fit.

Then, the M4 Mac mini came out. As I've considered a purchase, it has me rethinking my entire setup.

Read more