New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
ID: b40714ee-6581-566a-b514-2b95d5f3ebdc
STIX ID: report--b40714ee-6581-566a-b514-2b95d5f3ebdc
Feed Name: cybersecurityNews.com
**LegacyHive (MSNightmare)** is a Windows zero-day local privilege escalation that abuses the User Profile Service to mount an administrator's UsrClass.dat into a low-privileged user's registry, enabling modification of file associations, COM objects, and shell extensions to achieve persistence and admin-level code execution; a public PoC exists, Microsoft is investigating, and defenders are advised to restrict local admin logins, segment admin workstations, and monitor registry/COM changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
