Symantec Blogs: Security ResponseSyndicate content

Orlando Padilla | December 1st, 2006
0 comments

The long anticipated Windows Vistaoperating system is finally out the door and as anyone would agree,it’s celebration time at Microsoft. But, let’s discuss what we are infor with a peek at the default user environment on the 32-bit platform.

Symantec Advanced Threat Research decided to conduct an analysis ofWindows Vista’s security enhancements provided by the user accountcontrol (UAC) and resulting new security barriers. No formalrequirements were defined, although a few guidelines were set to stayorganized; gather a sample set of malicious code, execute them underthe default UAC environment, and carefully determine their success. Theresults were then broken down into three categories:
1) Successful execution of malicious code
2) System restart survivability
3) Failed execution of malicious code, and why

There are two important prerequisites in place to establish fair play practices:
1) All malicious code must be executed under...