logo

LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives

ID: 8fc928ef-b836-5414-a2cf-86ceb0a86336

STIX ID: report--8fc928ef-b836-5414-a2cf-86ceb0a86336

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Divya

...
...

LegacyHive is a locally exploitable Windows vulnerability demonstrated by a restricted C++ proof-of-concept that abuses the User Profile Service to mount a target user's UsrClass.dat hive into a lower-privileged account's registry view. This can allow a non-administrative user with access to another standard user's credentials and knowledge of the target username to modify administrator-level per-user registry settings (file associations, COM registrations, etc.), potentially enabling code execution in the administrator's context. The issue affects supported Windows desktop and Server builds (including July 2026 updates per the report), has been independently observed, and currently has no assigned CVE or vendor patch; defenders are advised to restrict local access, monitor ProfSvc activity and unexpected hive mounts, and investigate changes to user-level COM registrations and file associations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.