Local User account can access files of Administrator account, BUG?


  1. Posts : 6
    Windows 10
       #1

    Local User account can access files of Administrator account, BUG?


    Hello,

    I've created a Local account (Standard User) for family members to use my PC without having access to my personal files in my Administrator account. The problem is that I've noticed that you can bypass the password required to access the administrator's folder from the local account by just directly searching for files in the search bar.

    Pictures:

    Imgur: The magic of the Internet

    Windows Pro version 21H2 (OS BUILD 19044.1586)
      My Computer


  2. Posts : 15,499
    Windows10
       #2

    But can you actually open files?
      My Computer


  3. Posts : 6
    Windows 10
    Thread Starter
       #3

    cereberus said:
    But can you actually open files?
    Yes.
      My Computer


  4. Posts : 17,011
    Windows 10 Home x64 Version 22H2 Build 19045.4170
       #4

    Might you have given access permission for that Admin's user folder to the std user account while you set it up?
    Giving such permission to that folder is permanent but can be undone by examining & altering the properties of that folder while you are logged in as the Admin [which I assume means an Admin account you created rather than the Built-in Admin].
    Change Permissions - TenForumsTutorials

    By the way, you can post diagrams directly in your post.
    How to Upload and Post Screenshots and Files - TenForumsTutorials

    All the best,
    Denis
      My Computer


  5. Posts : 6
    Windows 10
    Thread Starter
       #5

    Try3 said:
    Might you have given access permission for that Admin's user folder to the std user account while you set it up?
    Giving such permission to that folder is permanent but can be undone by examining & altering the properties of that folder while you are logged in as the Admin [which I assume means an Admin account you created rather than the Built-in Admin].
    Change Permissions - TenForumsTutorials

    By the way, you can post diagrams directly in your post.
    How to Upload and Post Screenshots and Files - TenForumsTutorials

    All the best,
    Denis
    Hi, I didn't give any permissions to the standard account while setting it up, in fact you're not given any way to do so when creating it. As you can see in the screenshot guest1 (standard account) doesn't even appear in the list, there's just system, my administrator account and administrators.

    - - - Updated - - -

    Update: For some reason, it appears that when creating a local account (standard user) windows automatically gives it permission to access files in the administrator folder (at least on my machine). So the solution is to add the local account to the list of users in the security tab of the administrator folder and deny the permissions.
      My Computer


  6. Posts : 39
    Windows 10 1511
       #6

    The behavior you see is most probably, because the file "plan1.png" has access granted for the weak user. verify that. In that case, the behavior is normal and expected, since windows allows bypass traverse checking by default (which means, although the weak user may not enter c:\users\admin, he can still find files below it and access them if he's entitled to).
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:21.
Find Us




Windows 10 Forums