Updated: July 9, 2020 (December 4, 2006)
Analyst ReportUser Account Control Limits Exploit Impact
Following the lead of competing OSs such as Apple OS X and Linux, Windows Vista will allow users to run with the least privilege needed to perform a task such as running an application or installing new software. Using the least possible privilege to perform a task limits the damage that a mistake or malicious software can inflict on a computer, because such attacks operate in the security environment of the current user, and if that user’s security environment forbids access to system files or services, the attacker is similarly limited. However, because many Windows applications assume that users have administrative privileges, Microsoft has tried to balance security and reliability with application compatibility.
The Problem of Privilege
Windows NT, Windows 2000, and Windows XP all allow different users to be assigned different privileges, such as rights to create a new account, install software, or open a file for backup. In addition, specially privileged user accounts (system, local, and network service) are used by Windows’ Service Control Manager, which runs various Windows OS services and processes that run for all users and applications under these specialized system accounts.
Atlas Members have full access
Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.
Membership OptionsAlready have an account? Login Now