PortsuppeApp
SearchSourcesAboutDE/EN

Bypassing Administrator Protection by Abusing UI Access

Google Project Zero·104d·Official

In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed. In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the implementation of UI Access, how this has been a long standing problem with UAC that’s been under-appreciated, and how it’s being fixed now. A Question of Accessibility Prior to Wind

Categories cybersecurity
Original source / advisory
Published
2/11/2026, 11:00:00 PM
Fetched
5/27/2026, 4:13:24 AM
Trust
official · 100/100
Language
en