Comment Re:Does this really work? (Score 1) 316
The shim wouldn't actually grant any additional privileges to the app, of course. Look at what Vista already does - if a program attempts to write to the Program Files directory, the write gets redirected to an area in the user's profile folder. For non-filesystem calls, I'd imagine that the shim would request elevation through the usual means - i.e., UAC.