“Shatter Attacks - How to break Windows.”
https://web.archive.org/web/20060904080018/http://security.t...
“Shatter Attacks - How to break Windows.”
https://web.archive.org/web/20060904080018/http://security.t...
This one is way more indirect and goes through obscure and less reviewed channels, but the end result is kind of the same, even worse; because the integrity level was supposed to fix that mess, except MS was not lying when they said that this was not a security boundary... only they did explain the full picture properly explain so that we could understand that UAC is this much worthless -- lots of people thought of it as reasonable enough when set on Always notify, turns out it seems just plainly broken -- and because there seems to be no proper design comprehensively focused on that topic, it is very possible that there are other avenues to achieve the same result.
I think I now understand way better why they want so much (and have started since some years) to leverage virtualization for security purposes: it seems impossible for them to evolve their historical crappy design to something sound (without breaking all kind of crazy 3rd party applications) otherwise.