Have a Win 7 box, SP1, with default UAC settings (just for the feeling). When I run something as Administrator, the UAC elevation prompt comes up, asking for an admin password. That's designed behaviour (I wouldn't call it normal, though).
What bothers me is that the "Ok" button is selected by default. So if some sneaky badware gets to run on my box I have a chance of accidentally hitting Enter and thus allowing it run in privileged mode. I would expect it to default to "Cancel" or even start with the focus on a passive object so that unexpected appearance of the elevation prompt will not cause an accidental allowance (or denial) of the elevation request.
What do you think about this? (Other than switching UAC off.) Is there any way of settings the default?
UPDATE: this is because I had no password set for the admin user. Now that I have set and administrator password, the Yes button is still default, but obviously, can't accidentally accept it, since the password is required.