malware-log.hatenablog.com • 18h
Microsoft Windows LegacyHive ProfSvc Zero-Day Bypass
The LegacyHive vulnerability is a critical local privilege escalation (LPE) flaw residing in the Windows User Profile Service (ProfSvc). Discovered by researcher Nightmare Eclipse, the exploit enables low-privileged users to bypass the July 2026 security patches by forcing the service to load arbitrary registry hives belonging to other users. By manipulating the hive-loading mechanism, an attacker can gain SYSTEM-level access across both Windows desktop and server environments. The availability of a public proof-of-concept (PoC) significantly increases the risk of immediate exploitation in the wild, rendering recent Microsoft security updates insufficient against this specific vector.