@cluberti the security vulnerability is still there, because only one app with this manifest entry can be used to bypass the uac when the uac is running at the default level. I also able to inject notepad, dwm, explorer and a lot more app to run any code in elevated mode without accepting the UAC prompt. Mark posted that MSFT knows this issue and will never fix it. Look here for a video: http://nudel.kelbv.com/W7E_VID_INT/W7E_VID_INT.htm and take a look at the demo app+code: http://www.pretentiousname.com/misc/W7E_So...Inject.cpp.html