UAC & secure desktop -- Is it a hole??

K

krzysiek

Hi I just found that secure desktop doesn't working as it should ( please
correct me if I'm wrong ;] ) I thing that secure desktop has a hole.. If You
run priviledged application You can switch to other window using alt+tab and
UAC will be minimized ;) I don't think is should be like that... I didn't
tried yet, if is possible to send any messages to that window from other
application, if Yes I think it is not a small hole, becouse programs can
gives some permission to run priviledged applications..

I made small screen capute which shows that, but unfortunally when UAC works
then capturing doesn't work, so You can see only blinking icon on the task
bar.
If You want You can see it on


But better is to try it ;)
What You think about it??

cU ;)
 
B

BillD

krzysiek said:
Hi I just found that secure desktop doesn't working as it should ( please
correct me if I'm wrong ;] ) I thing that secure desktop has a hole.. If You
run priviledged application You can switch to other window using alt+tab and
UAC will be minimized ;) I don't think is should be like that...

It's a not a flaw, the UAC prompt will appear when you maximize the Window,
you can't bypass it:
http://blogs.msdn.com/uac/archive/2006/09/05/741318.aspx
"Other improvements besides prompt reduction that we’ve made to Windows
Vista RC1 are:
UAC prompts will not “steal focus†from the user’s task. If the operating
system cannot determine that the prompt was generated from the foreground
window the current user is using, we will alert the user with a highlighted
operation in the taskbar that an application is requesting elevated
privileges. The user can select to elevate at his or her convenience and not
be disrupted by an unplanned application elevation."
 
L

Louis

krzysiek said:
Hi I just found that secure desktop doesn't working as it should ( please
correct me if I'm wrong ;] ) I thing that secure desktop has a hole.. If
You
run priviledged application You can switch to other window using alt+tab
and
UAC will be minimized ;) I don't think is should be like that... I didn't
tried yet, if is possible to send any messages to that window from other
application, if Yes I think it is not a small hole, becouse programs can
gives some permission to run priviledged applications..

I made small screen capute which shows that, but unfortunally when UAC
works
then capturing doesn't work, so You can see only blinking icon on the task
bar.
If You want You can see it on

The video is not very clear to me.
My english is not so good and I may have missed something.
Can you explain step by step what you did? Did you disable anything from the
defaul Vista settings?
Because, in my Vista, if I log with administrator privileges and I try to
run applications that require the elevation, the "secure desktop" will work
exactly as I read it should work:
the background and desktop will became grey and inactive and the only active
window is the UAC, and even clicking on alt+tab I can't focus any other
opened program, like it seems you did on that video.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

UAC security hole? 1
Secure Desktop question 2
UAC setting blocking auto run... 1
Defender, Startup programs, and UAC 16
Disable UAC and warning dialog? 4
UAC On and OFF 10
UAC question 3
question about uac shield icon 2

Top