Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Administration > Flaw in UAC/User Accounts

Reply
Thread Tools Display Modes

Flaw in UAC/User Accounts

 
 
McFingers
Guest
Posts: n/a

 
      09-28-2007
Hi All!!

Upon making a Limited User account while making a How-To guide for Vista,
stumbled upon this flaw.

A Limited User is able to make an Aministrator User. Therefore bypassing the
Parental Controls and safety regarding the whole reason for making a Limited
User.

A Limited User should have just house permissions....Limited.

I am not sure if blocking access to the control panel applet/MSC or control
useraccounts applet/MSC would remedy the probem. Hopefully MS will address
and fix this issue before the release of SP1, or make a HotFix for it and put
it on their Update Server.


----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://windowshelp.microsoft.com/com...unts_passwords
 
Reply With Quote
 
 
 
 
Philip Ulrich
Guest
Posts: n/a

 
      09-29-2007
What? How? Sounds like bull to me.

--
- It's always Microsoft's fault no matter what your problem is.

 
Reply With Quote
 
Ronnie Vernon MVP
Guest
Posts: n/a

 
      09-30-2007
McFingers

What you are describing is not possible in Vista?

If you are logged on with a Standard account and attempt to access any part
of Control Panel/User Accounts where you can create a new account or even
change a current account, you must elevate that process using an
administrator account credentials.

There are only 2 settings possible for a Standard account in Vista when
starting a process that requires elevation to administrator privileges.
1. Prompt for administrator privileges where an administrator account and
password must be entered.
2. Deny any elevation.

Even if UAC is turned off and you try to create or change a user account,
(or any other task that requires administrator privileges) you may actually
be able to go through the process, but the changes will silently fail to
take effect. A new administrator user account will not be created and any
changes to any current account (such as changing a standard user to an
administrator account) will fail to take effect.



--

Ronnie Vernon
Microsoft MVP
Windows Shell/User


"McFingers" <> wrote in message
news:BE022208-01FB-4D91-B3BE-...
> Hi All!!
>
> Upon making a Limited User account while making a How-To guide for Vista,
> stumbled upon this flaw.
>
> A Limited User is able to make an Aministrator User. Therefore bypassing
> the
> Parental Controls and safety regarding the whole reason for making a
> Limited
> User.
>
> A Limited User should have just house permissions....Limited.
>
> I am not sure if blocking access to the control panel applet/MSC or
> control
> useraccounts applet/MSC would remedy the probem. Hopefully MS will
> address
> and fix this issue before the release of SP1, or make a HotFix for it and
> put
> it on their Update Server.
>
>
> ----------------
> This post is a suggestion for Microsoft, and Microsoft responds to the
> suggestions with the most votes. To vote for this suggestion, click the "I
> Agree" button in the message pane. If you do not see the button, follow
> this
> link to open the suggestion in the Microsoft Web-based Newsreader and then
> click "I Agree" in the message pane.
>
> http://windowshelp.microsoft.com/com...unts_passwords


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
user accounts with different email accounts brat38 Windows Vista Networking 0 05-10-2008 04:33 AM
user accounts mel78 Windows Vista Administration 1 01-03-2008 05:12 PM
user accounts don't show up on manage accounts DavidDuffy Windows Vista Administration 0 10-10-2007 11:30 PM
user profile and user accounts larry Windows Vista Administration 1 09-11-2007 05:57 PM
Standard user accounts can access files of other accounts??!! Ralf Windows Vista Administration 0 06-04-2007 10:53 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59