LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
ID: fdbfebfc-677f-56f5-beb4-c81ccca968c6
STIX ID: report--fdbfebfc-677f-56f5-beb4-c81ccca968c6
Feed Name: The Register (Security)
Threat Score
LegacyHive is a Windows local privilege escalation zero-day published by the researcher known as NightmareEclipse that abuses the profsvc User Profile Service to mount other users' registry hives (including admin hives). The public proof‑of‑concept is intentionally limited—restricted to usrclass.dat and requiring credentials—but experts warn capable attackers could fill the gaps and weaponize the bug quickly; Microsoft is investigating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
