5 ms·
https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works https://learn.microsoft.com/en-us/
by Scion9066 3y ago
https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works https://learn.microsoft.com/en-us/windows/security/applicati...
> If the policy setting is set to Prompt for credentials, malware imitating the credential prompt might be able to gather the credentials from the user. However, the malware doesn't gain elevated privilege and the system has other protections that mitigate malware from taking control of the user interface even with a harvested password.
So just knowing the credentials is not enough, they have to be used in the right context (the secure desktop).