Sophos claim Microsoft left Windows 7 open to hackers

'Neutered' UAC misses 7 of 8 trojans

Microsoft's decision to reduce the number of annoying security messages that Windows 7 delivers when users install software makes the new operating system more vulnerable to malware infection than Vista, a researcher said today.

"UAC was neutered too much by Microsoft," argued Chester Wisniewski, a senior security advisory with Sophos, talking about Windows' Users Account Control (UAC), the security feature Microsoft debuted with Vista.

UAC prompts users for their consent before allowing tasks such as program and device driver installation to take place. In an effect to quash user complaints which had condemned the constant intrusions, Microsoft modified UAC so it appears less frequently in Windows 7.

That wasn't a good idea, said Wisniewski.

"We wanted to know if UAC was going to be effective in Windows 7," he said. "So we grabbed the next 10 [malware] samples that came in and tried them out."

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

The 10 samples, most of them Trojan horses, were loaded onto a clean Windows 7 PC that lacked antivirus software, simulating payloads that an actual exploit would deposit on a compromised computer. Wisniewski then ran each piece of malware, as if a user had been duped into launching a file attachment or had surfed to a malicious site and been victimized by an drive-by attack and subsequent silent download.

Of the 10 samples, two would not run under Windows 7, not surprising since they were likely designed to execute on the far more common Windows XP and Vista, and only one of the remaining eight triggered an UAC prompt, said Wisniewski.

He acknowledged that the test was quick and dirty, and didn't accurately portray how secure Windows 7 was overall, or even how well it would withstand attack if protected by antivirus software, even basic programs like Microsoft's free Security Essentials. The point was to see how much Windows 7's reconfigured UAC would help block malware that made it past security software or got by other defensive measures of the operating system, like DEP (Data Execution Protection) and ASLR (Address Space Layout Randomisation).

"UAC is really not protecting users properly," Wisniewski said. "Frankly, people should turn it back into the more aggressive mode, like Vista," he said, speaking of the ability to set the feature's prompting frequency. "And if you find it annoying, you might just as well turn it off, because otherwise it's not doing any good."



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Enterprise mashup services

Mashups are part of the Web 2.0 evolution of IT that can empower a business to enhance productivity, innovate more readily and collaborate more effectively – both internally, and with suppliers, partners and customers

10 key actions to reduce IT infrastructure and operations cost structure

Infrastructure and operations leaders are under intensifying pressure to reduce costs. This research outlines the key actions they should take to change the I&O cost structure near term (through 2010) and longer term (during the next three years).

Unlocking the benefits of Google Apps

Download this whitepaper to learn more about how you can save time and money by migrating from Microsoft Exchange to Google Mail.

Achieving Control: The four critical success factors of change management

Improve IT business value with minimum impact on security compliance and IT infrastructure


CIO UK - Business - Technology - Leadership

Nimsoft  White Paper

Ensuring high service levels in cloud computing

Explore the most pressing challenges cloud computing presents in terms of service level management and how to overcome obstacles

A comprehensive overview of key issues organisations should be aware of before they make the plunge to cloud computing.

Read more

CIO Survey: Win a Sony e-book reader

The recession has influenced many companies across the globe, prompting them to re-evaluate their business strategies, adjust their budgets and focus on new initiatives to enhance their organisations success. CIO is carrying out a survey in order to discover how the recession has affected you. Share your experiences and discover how other companies have adapted their infrastructures and perception of their IT teams in today’s trying times.

Complete the survey

Transforming cost and budget data into easy to understand information

Download this white paper to learn how to improve your IT financial management systems. Many companies today use manually crafted spreadsheets or expensive homegrown systems to provide critical planning information for budgeting, decision support, and chargeback. With pre-built data integration, data cleansing, and a central repository for cost information, Financial Planning & Analysis (FPA) software helps you significantly reduce the effort involved in transforming cost and budget data into easy-to-understand cost information.
Download the whitepaper




* *