3 ms·
> No consumer OS since Windows Me logs in with a system account by default. About that. > It’s important to be aware that UAC elevations are conveniences and
by RaleyField 11y ago
> No consumer OS since Windows Me logs in with a system account by default.
About that.
> It’s important to be aware that UAC elevations are conveniences and not security boundaries.
https://technet.microsoft.com/en-us/magazine/2007.06.uac.aspx https://technet.microsoft.com/en-us/magazine/2007.06.uac.asp...
>unfortunately, this is also where we run into some of the limitations of UAC. Remember, there is no effective isolation; there is no security boundary that isolates processes on the same desktop. The OS does include some protective measures to keep the obvious and unnecessary avenues of communication blocked, but it would be impossible and undesirable to block them all. Therefore, Microsoft does not consider breaches of that nonexistent security boundary to be security breaches.
https://technet.microsoft.com/en-us/magazine/2007.09.securitywatch.aspx https://technet.microsoft.com/en-us/magazine/2007.09.securit...
In default and probably usual configuration UAC does not represent security boundary between medium-il (user) an high-il (equivalent of linux's root). Only if you bother to run under non-admin account are you protected from escalations.
Leo Davidson then provided demonstrations of privilege escalation between those two integrity levels without triggering uac.
I haven't checked Windows 10, but at least until Windows 8 most machines running Windows had been running most software effectively under root.