Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html

ONE SENTENCE SUMMARY:

LegacyHive PoC highlights unpatched Windows ProfSvc hive-load EoP, while July 2026 patches address actively exploited SharePoint and ADFS flaws.

MAIN POINTS:

  1. Chaotic Eclipse released LegacyHive, a ProfSvc arbitrary hive-load elevation-of-privilege PoC.
  2. Exploit mounts a target user hive under the attacker’s current user classes root.
  3. PoC needs another standard-user credential and a third username, possibly administrator.
  4. Researcher claims original exploit required no extra credentials and wasn’t limited to usrclass.dat.
  5. Vulnerability could load any registry hive, though PoC was intentionally constrained.
  6. LegacyHive reportedly works on all supported Windows versions, including July 2026-patched systems.
  7. Ongoing dispute exists between Chaotic Eclipse and Microsoft over disclosure and communication breakdowns.
  8. Previously disclosed Defender issues saw active exploitation soon after public release of details.
  9. July 2026 Patch Tuesday shipped fixes for 622 flaws, including exploited SharePoint and ADFS CVEs.
  10. CISA warns SharePoint flaws enable RCE, key theft, deserialization persistence, and malware deployment.

TAKEAWAYS:

  1. Treat LegacyHive as evidence of a broadly compatible Windows EoP still affecting fully patched machines.
  2. Tighten controls around local user credentials and profile/hive handling to reduce privilege escalation paths.
  3. Prioritize patching KEV-listed SharePoint and ADFS vulnerabilities by CISA’s mandated deadlines.
  4. Assume internet-facing on-prem SharePoint is high-risk due to remote, sometimes unauthenticated exploitation.
  5. Monitor Defender and SharePoint update side-effects, including potential data leakage and chaining opportunities.