logo

LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives

ID: dee10ee7-3b1b-5c9a-894c-350a784d6704

STIX ID: report--dee10ee7-3b1b-5c9a-894c-350a784d6704

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Tamilselvan

...
...

## Executive summary A proof-of-concept named LegacyHive exploits inconsistent access-control when Windows loads an administrator's Classes hive (usrClass.dat), allowing a non-admin user to gain write access via a SYSTEM fallback and plant registry changes (file associations or COM registrations) that execute with administrator privileges when the admin next logs in. The issue is a local privilege escalation zero-day with demonstrated PoC, no patch at publication, and significant detection challenges in shared or multi-user environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.