August 2, 2009
4:52 am

Leo Davidson released a proof-of-concept showcasing Windows 7 User Account Control feature flaw elevating a command prompt window using the whitelisted explorer.exe process. As of now, Microsoft has failed to fix the flaw, but they’re taking it a step further by blocking the exploit in Microsoft Security Essentials, as HackTool.Win32/Welevate.A and HackTool.Win64/Welevate.A (depending on architecture).  However, Leo noted that Windows Defender in Vista did not detect this exploit, and Bryant confirmed that the same is true for Windows 7 (where the trick would actually work), so this seems to be exclusive to Microsoft Security Essentials.

Loading

Contextual Related Posts:

No comment yet

Leave a comment »

  1. Pingback from
    1
    Microsoft Security Essentials lists Windows 7 UAC hack as malware | www.windows7vista.com says:August 2nd, 2009 at 3:16 pm

    [...] Microsoft Security Essentials lists Windows 7 UAC penetrate as malware Share and [...]

Leave a Response

Comment Preview
« Installing Integration Services in Hyper-V Guest – VideoFCC investigating Apple’s rejection of Google Voice Apps »
Feed Icon

Subscribe via RSS or email: