Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
ONE SENTENCE SUMMARY:
LegacyHive PoC highlights unpatched Windows ProfSvc hive-load EoP, while July 2026 patches address actively exploited SharePoint and ADFS flaws.
MAIN POINTS:
- Chaotic Eclipse released LegacyHive, a ProfSvc arbitrary hive-load elevation-of-privilege PoC.
- Exploit mounts a target user hive under the attacker’s current user classes root.
- PoC needs another standard-user credential and a third username, possibly administrator.
- Researcher claims original exploit required no extra credentials and wasn’t limited to usrclass.dat.
- Vulnerability could load any registry hive, though PoC was intentionally constrained.
- LegacyHive reportedly works on all supported Windows versions, including July 2026-patched systems.
- Ongoing dispute exists between Chaotic Eclipse and Microsoft over disclosure and communication breakdowns.
- Previously disclosed Defender issues saw active exploitation soon after public release of details.
- July 2026 Patch Tuesday shipped fixes for 622 flaws, including exploited SharePoint and ADFS CVEs.
- CISA warns SharePoint flaws enable RCE, key theft, deserialization persistence, and malware deployment.
TAKEAWAYS:
- Treat LegacyHive as evidence of a broadly compatible Windows EoP still affecting fully patched machines.
- Tighten controls around local user credentials and profile/hive handling to reduce privilege escalation paths.
- Prioritize patching KEV-listed SharePoint and ADFS vulnerabilities by CISA’s mandated deadlines.
- Assume internet-facing on-prem SharePoint is high-risk due to remote, sometimes unauthenticated exploitation.
- Monitor Defender and SharePoint update side-effects, including potential data leakage and chaining opportunities.