LegacyHive: Video demo and analysis of Windows 0-day from NightmareEclipse
ID: 94dd3ee0-5636-5f6d-8bc9-1f13c53e5621
STIX ID: report--94dd3ee0-5636-5f6d-8bc9-1f13c53e5621
Feed Name: ThreatLocker Blog
NightmareEclipse published LegacyHive, a proof-of-concept exploit that leverages Object Manager symbolic links and manipulated profile hive paths to mount another user's UsrClass.dat hive on fully patched Windows systems; while the PoC is incomplete and not immediately weaponized to reveal passwords or execute privileged code, it demonstrates a path-resolution vulnerability affecting desktop and server installations, provides IOCs and detection guidance, and recommends auditing and monitoring of profile hive access and related API/event activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
