The debate about UAC and circumventing the prompt continues... From my perspective it's more a misunderstanding at this point than anything that merits any analysis... Look...between you and me...malware writers are much more talented than anyone's giving them credit for...
Here are the current posts that present the story "security flaw":
http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-some-other-day/
http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/
Mark Russinovich's article pretty much tells the story from a technology perspective: http://technet.microsoft.com/en-us/magazine/2009.07.uac.aspx
I wrote the following as a comment to the first blog post I pasted above - it talks more about the history of UAC...
---
Posted
Jun 18 2009, 09:45 PM
by
Chris Corio