5 ms·
That's not the point they were trying to make. They were asking what would prevent malware from imitating the UAC prompt to steal administrator privileges.
by asimops 2y ago
That's not the point they were trying to make. They were asking what would prevent malware from imitating the UAC prompt to steal administrator privileges.
- DEADMINCE 2y agoI understand and answered that. The answer is Secure Desktop, details on which can be found in the link I posted in my earlier comment.
- Scion9066 2y agohttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works https://learn.microsoft.com/en-us/windows/security/applicati... > If the policy setting is set to Prompt for credentials, malware imitating the credential prompt might be able to gather the credentials from the user. However, the malware doesn't gain elevated privilege and the system has other protections that mitigate malware from taking control of the user interface even with a harvested password. So just knowing the credentials is not enough, they have to be used in the right context (the secure desktop).