Security Concern Regarding Microsoft 'PC Manager' App

Nav 0 Reputation points
2024-04-06T06:33:10.3066667+00:00

Dear Microsoft Support Team,

I am writing to bring to your attention a concerning security issue that has been observed with the recently released Microsoft "PC Manager."

Upon conducting thorough testing and analysis, it has come to our attention that there are significant security vulnerabilities when the PC Manager is being used by non-administrator (limited user) accounts. Specifically, limited users have full control over various critical features within the PC Manager interface, which should ideally be restricted to administrator-level access only.

One of the most alarming findings is that non-admin users have the ability to manipulate recommended startup applications, including stopping (turning on and off) essential processes such as the "MS-Anti Virus" application. This capability poses a severe risk as it allows unauthorized users to disable crucial security measures, compromising the overall system integrity.

Additionally, non-admin users can access the process manager within PC Manager and terminate tasks indiscriminately. While some level of control over task management may be permissible for limited users, the current setup grants them unrestricted access, enabling them to terminate processes that should only be managed by administrators.

These issues undermine the fundamental principles of user access control and pose significant security risks to systems running the PC Manager application. It is imperative that these vulnerabilities be addressed promptly to ensure the safety and integrity of users' systems.

We urge the Microsoft development team to investigate these security concerns thoroughly and implement necessary fixes or updates to mitigate the risks associated with PC Manager usage by non-administrator accounts. Enhancing access control mechanisms and restricting certain functionalities to administrator-level permissions would greatly enhance the overall security posture of the application.

Please consider this communication as a constructive effort to improve the security of Microsoft products, and we would appreciate any updates or insights you can provide regarding the resolution of these issues.

Thank you for your attention to this matter, and we look forward to your prompt response.

Sincerely,

Service Manager
Service Manager
A family of System Center products for managing incidents and problems.
209 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,756 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,191 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
103 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jing Zhou 2,240 Reputation points Microsoft Vendor
    2024-04-10T09:20:31.6333333+00:00

    Hello,

    Thank you for posting in Q&A forum.

    Thank you very much for your valuable feedback and suggestions. We would greatly appreciate it

    Microsoft has a dedicated address for publishing feedback, please refer to

    Send feedback to Microsoft with the Feedback Hub app - Microsoft Support

    Best regards,

    Jill Zhou

    0 comments No comments