Perhaps I'm using the wrong terminology. Actually, file and directory ACL's are a very important part of Windows security. Where I've seen this come into play is when running IIS. If the user under which IIS runs does not have proper access to the site document root then some file manipulations are not possible. However, my knowledge of Apache on Windows is somewhat limited. By default, Apache2 runs under Local System which should be fine in most cases. Even running under a local computer admin account the files are still not deleted. You are correct in assuming it may be the code behind the image uploader (found at the Write post screens) in Wordpress 2.0....I would be curious to see if you can duplicate this with your own install of WP2.0 on the latest version of the Uniform Server. UServer is a great product and I'm really frustrated with trying to get this file deletion problem solved.