I would like to add that if UAC can be disabled this easily then that is just the tip of the iceberg. Which is to say that if UAC can be changed then effectively everything accessible in Control Panel can be. So even if Microsoft hot fix the UAC secure
window to block this then they really haven't solved much of anything.
Really makes one wonder if Windows needs an entire concept of "User actions" Vs. "Program action" from the driver level on down though to all applications. But that might require a complete redesign of the OS.
PS - KevinB I run Vista with UAC, DEP ("All Programs"), and passive anti-virus/spyware.