
An anonymous researcher operating under the pseudonym NightmareEclypse has published exploit code for a Windows vulnerability on the same day Microsoft released a record volume of security patches. The flaw, named HiveLegacy, is classified as an elevation-of-privilege exploit targeting the Windows User Profile Service.
The vulnerability enables users with limited system permissions to modify sensitive registry settings associated with administrator accounts. Specifically, the exploit allows attackers to alter a target admin account’s classes registry hive, which determines which application launches when users interact with specific file types in Windows Explorer. According to researchers who have examined the code, the technique functions as described, though the published proof-of-concept was deliberately limited to reduce potential for malicious misuse.
Security analysts characterize HiveLegacy as a “powerful primitive” with significant implications. The attack requires the attacker to possess credentials for at least one non-administrator user account and knowledge of the target administrator’s username. Will Dormann, a senior principal vulnerability analyst, noted that once an attacker establishes the ability to execute code upon an administrator’s login, they effectively obtain administrative privileges without holding such status themselves. Researchers suggest the exploit could potentially be combined with other vulnerabilities to achieve more direct administrative access.
This marks the ninth zero-day published by NightmareEclypse, who has previously expressed frustration with Microsoft’s handling of vulnerability disclosures. Microsoft stated it is investigating the report and reiterated its preference that researchers follow coordinated disclosure practices. In the interim, affected users can employ defensive measures including a detection script released by independent researcher Kevin Beaumont, restricting local account creation, monitoring the ProfSvc process for unexpected hive loading, and tracking activity related to NTUSER.DAT and UsrClass.dat files.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI