LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
ID: 8fc928ef-b836-5414-a2cf-86ceb0a86336
STIX ID: report--8fc928ef-b836-5414-a2cf-86ceb0a86336
Feed Name: GBHackers
LegacyHive is a locally exploitable Windows vulnerability demonstrated by a restricted C++ proof-of-concept that abuses the User Profile Service to mount a target user's UsrClass.dat hive into a lower-privileged account's registry view. This can allow a non-administrative user with access to another standard user's credentials and knowledge of the target username to modify administrator-level per-user registry settings (file associations, COM registrations, etc.), potentially enabling code execution in the administrator's context. The issue affects supported Windows desktop and Server builds (including July 2026 updates per the report), has been independently observed, and currently has no assigned CVE or vendor patch; defenders are advised to restrict local access, monitor ProfSvc activity and unexpected hive mounts, and investigate changes to user-level COM registrations and file associations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
