According to research conducted by Avecto, Windows users who log in as “standard users” on their computers minimize the likelihood of exposure to critical vulnerabilities involving Microsoft products by 90%, compared to users who log in as “administrators”.
The company looked at 333 vulnerabilities reported by Microsoft in 2013 (based on monthly Security bulletins), finding that 60 percent of these vulnerabilities could have been mitigated if administrator privileges had been disabled. Furthermore, for the 147 security vulnerabilities identified in Microsoft products and rated as critical, the mitigation level reached an astonishing 92 percent.
Regarding each product individually, Avecto found that 96% of critical vulnerabilities identified in all versions of Windows (up to Windows 8) were mitigated after disabling administrator rights, a percentage that reached 100% for Internet Explorer, 91% for Office, and 96% for Windows Server 2003, 2010, and 2012.
Additionally, more than half of the vulnerabilities could allow remote code execution if the user was logged in as an administrator.
“It’s amazing how many security vulnerabilities can be overcome by blocking administrator rights,” said Avecto co-founder and executive vice president Paul Kenyon.
"Even more striking is how many unknown and zero-day attacks also depend on the abuse of administrator privileges. Blocking these privileges is a simple way to reduce general vulnerabilities, even vulnerabilities that have not been patched," Kenyon argued.

