A couple of things here.
1. This report coming from an antivirus vendor is no huge shock.
2. Why isn't there any specifics about how it was installed? I don't see anything that specifically says that the malware installed with elevated priveledges, or whether it required the user to click ok to accept it? If its a case of the user accepting it, and it installing, well no duh it got through.
3. 10 hand picked viruses by Sophos. Did you think they would honestly pick ones that would be blocked? You can be sure they picked the cream of the crop for their test. On top of that, 10 viruses out of what, thousands? millions? Hardly a representative sample. This report was just Sophos pimping themselves out. Notice no note of MSE being released, and that its for XP, Vista,and 7? If MS felt UAC was enough on its own, then they probably wouldn't have bothered with MSE.
UAC cannot effectively block all malware, or viruses without heuristics or virus definitions, of which it has neither.
This post has been edited by adrynalyne: 06 November 2009 - 10:17 PM