Based on my quick browse (sorry, a bit busy right now), they still haven't a crucial flaw in the UAC system: any program that can pass itself off as an admin will get full access, and may actually hijack the escalation dialog to pass itself off as legit to a less savvy user.