A security researcher has released details of a Windows zero-day vulnerability dubbed LegacyHive that allows attackers to escalate privileges to administrator level on fully up-to-date Windows systems. The exploit takes advantage of legacy components in the Windows registry to bypass modern security protections.
The vulnerability, disclosed by a researcher using the alias Nightmare Eclipse, affects all supported versions of Windows. It exploits weaknesses in how the operating system handles specific registry hive operations, enabling a standard user account to gain SYSTEM-level privileges without triggering modern defense mechanisms.
LegacyHive works by manipulating older registry functions that were designed for backward compatibility but were never properly secured against modern attack techniques. The exploit chain involves writing specially crafted data to certain registry keys, which then triggers privileged operations when the kernel processes them.
Microsoft has been notified of the vulnerability. At the time of disclosure, no official patch had been released. The company may address the issue in a future Patch Tuesday update or release an out-of-band security fix depending on the severity of active exploitation.
Security experts recommend organizations review their Windows security configurations and apply the principle of least privilege to limit the potential impact of privilege escalation exploits. While the vulnerability requires an attacker to already have some level of access to a target system, it significantly lowers the barrier to full system compromise once a foothold is established.
This article was adapted from Bleeping Computer. Read the original here.
