Particle.news
Download on the App Store

LegacyHive PoC Lets Local Users Mount Other Accounts’ Registry Hives on Patched Windows

The public release intensifies a dispute over private vendor reporting, forcing defenders to rely on short-term mitigations and tighter local controls.

Overview

  • Chaotic Eclipse published the LegacyHive proof-of-concept hours after July Patch Tuesday, demonstrating a flaw in the Windows User Profile Service that can load another user’s registry hive on fully patched desktop and server Windows.
  • Exploitation requires local access, valid credentials for a second account, and an additional local profile, which makes the bug useful for post-compromise privilege escalation rather than mass remote attacks.
  • Microsoft has been notified and is investigating LegacyHive but has not yet assigned a CVE, issued an advisory, or provided a security update for the issue.
  • The release continues a months-long public dispute between Chaotic Eclipse and Microsoft’s Security Response Center over coordinated vulnerability disclosure and follows multiple earlier zero-day public disclosures.
  • Organizations are being urged to tighten local account controls, increase logging and monitoring for lateral movement, and apply separate July Patch Tuesday fixes that CISA added to its Known Exploited Vulnerabilities list.