It's a feature, not a bug
When confronted with user reports that the User Account Control (UAC) dialog in Windows 7 could be turned off by a simple piece of malware, Microsoft responded that this was “by design.”
That’s right. UAC was too ‘noisy’ in Vista, so Microsoft has allowed more user control of the feature. So much so, in fact, that now a simple VBScript can turn it off without the user’s knowledge.
The mind boggles.