Windows 0-day drops the same day Microsoft releases record number of patches
ID: c7232a90-08a4-5837-bcbc-1edf8bfc69e0
STIX ID: report--c7232a90-08a4-5837-bcbc-1edf8bfc69e0
Feed Name: Ars Technica Security (category)
Threat Score
A newly reported Windows vulnerability dubbed "HiveLegacy" allows a non-administrative user to modify an admin user's classes registry hive, enabling attacker-controlled code to run when the administrator logs in. Microsoft is investigating; researchers have published detection scripts and recommended mitigations such as restricting local non-user account creation and monitoring hive loads and NTUSER.DAT/UsrClass.dat activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
