The record
Written from the 1 report below. Nothing here is unsourced.
- A security researcher known as Nightmare Eclipse disclosed a Windows zero-day flaw, dubbed LegacyHive, in the Windows User Profile Service along with a proof-of-concept exploit, and Microsoft says it is investigating.
- The flaw lets a non-admin user modify another user's registry hive to gain code execution when an admin logs in, and it affects Windows 10 2004 and later and Windows Server 2019 and later.
- Since Microsoft has not yet released an official fix, ACROS Security has issued free unofficial micropatches through its 0Patch platform that work without a system restart.
- Other flaws disclosed by the same researcher, such as BlueHammer, RedSun, and UnDefend, are still awaiting patches.
What to watch next
- Whether Microsoft assigns a CVE ID and ships an official fix in an upcoming Patch Tuesday update
- Any signs of LegacyHive being actively exploited in real-world attacks
- Patching of the remaining unpatched Nightmare Eclipse disclosures like BlueHammer, RedSun, and UnDefend
Coverage1
1 report
International1
All filed from United States
Named United States · 0Patch · Microsoft · Microsoft Defender for Endpoint · Windows · ACROS Security · Kevin Beaumont · Mitja Kolsek · Nightmare Eclipse · Tharros · Will Dormann
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
