LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
ID: dee10ee7-3b1b-5c9a-894c-350a784d6704
STIX ID: report--dee10ee7-3b1b-5c9a-894c-350a784d6704
Feed Name: Cyber Press
## Executive summary A proof-of-concept named LegacyHive exploits inconsistent access-control when Windows loads an administrator's Classes hive (usrClass.dat), allowing a non-admin user to gain write access via a SYSTEM fallback and plant registry changes (file associations or COM registrations) that execute with administrator privileges when the admin next logs in. The issue is a local privilege escalation zero-day with demonstrated PoC, no patch at publication, and significant detection challenges in shared or multi-user environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
