Re: Windows Vista winsat.exe Integer Overflow

Steve Shockley <[email protected]> Fri, 28 Mar 2008 23:03:55 -0400
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
[email protected] wrote:
> if you can control the
> process, you can use this kind of bugs as way to trick the user to
> bypass the UAC and get admin.

You'd still have to convince the user to bypass UAC when he wasn't 
expecting a UAC prompt, in addition to getting them to run it in the 
first place.