logo

New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access

ID: b40714ee-6581-566a-b514-2b95d5f3ebdc

STIX ID: report--b40714ee-6581-566a-b514-2b95d5f3ebdc

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Abinaya

...
...

**LegacyHive (MSNightmare)** is a Windows zero-day local privilege escalation that abuses the User Profile Service to mount an administrator's UsrClass.dat into a low-privileged user's registry, enabling modification of file associations, COM objects, and shell extensions to achieve persistence and admin-level code execution; a public PoC exists, Microsoft is investigating, and defenders are advised to restrict local admin logins, segment admin workstations, and monitor registry/COM changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.