Developer Tools

Windows zero-day 'HiveLegacy' drops as Microsoft issues record patches

Low-privilege users can now hijack admin accounts via registry exploit.

Deep Dive

On the same day Microsoft released a record number of security patches, anonymous researcher NightmareEclypse published exploit code for a Windows zero-day dubbed HiveLegacy. The vulnerability resides in the Windows User Profile Service and allows low-privilege accounts to modify the classes registry hive of administrator accounts. This is an elevation-of-privilege (EoP) exploit that can enable attackers to compromise admin users by ensuring malicious code runs when the admin logs in. Multiple independent researchers, including senior vulnerability analyst Will Dormann, confirmed the exploit works, calling it a "pretty powerful primitive."

NightmareEclypse has published nine such exploits to date, each time complaining about Microsoft's handling of their bug reports. The proof-of-concept code was stripped down to prevent easy weaponization, but researchers warn that clever attackers can chain it with other exploits for full admin access. Microsoft stated it is aware of the report and is investigating, while recommending coordinated disclosure. Temporary mitigations include running a detection script by Kevin Beaumont, restricting local non-user account creation, monitoring ProfSvc for unexpected hive loads, and tracking NTUSER.DAT/UsrClass.dat activity.

Key Points
  • Zero-day 'HiveLegacy' targets Windows User Profile Service for EoP
  • 9th such disclosure from pseudonymous researcher NightmareEclypse
  • Exploit lets low-privilege users modify admin registry; requires known credentials
  • Multiple researchers confirm it works; Microsoft investigating
  • Temporary mitigations: detection script, restrict account creation, monitor hive loads

Why It Matters

Unpatched Windows zero-day enables low-privilege users to hijack admin accounts, escalating risk for enterprises.

📬 Get the top 10 AI stories daily