logo

Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems

ID: 560e71c7-3402-5eb5-aa44-e7004e1fb471

STIX ID: report--560e71c7-3402-5eb5-aa44-e7004e1fb471

Feed Name: Security Affairs

Threat Score
60/100

Date Published: 2026-07-15

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Security researcher "Chaotic Eclipse" published LegacyHive, a proof-of-concept local privilege-escalation vulnerability targeting the Windows User Profile Service that can mount another user's registry hive (potentially an administrator's) into the current user's profile. The PoC requires local access and additional valid credentials, has no CVE or patch at publication, and is primarily relevant to post-compromise operations; the disclosure continues a public dispute between the researcher and Microsoft over coordinated vulnerability handling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.