logo

Windows 0-day drops the same day Microsoft releases record number of patches

ID: c7232a90-08a4-5837-bcbc-1edf8bfc69e0

STIX ID: report--c7232a90-08a4-5837-bcbc-1edf8bfc69e0

Feed Name: Ars Technica Security (category)

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Dan Goodin

...
...

A newly reported Windows vulnerability dubbed "HiveLegacy" allows a non-administrative user to modify an admin user's classes registry hive, enabling attacker-controlled code to run when the administrator logs in. Microsoft is investigating; researchers have published detection scripts and recommended mitigations such as restricting local non-user account creation and monitoring hive loads and NTUSER.DAT/UsrClass.dat activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.