1mo ago · hacker-news
Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit named LegacyHive, which exploits a Windows User Profile Service vulnerability to load arbitrary hives and achieve privilege escalation. The exploit works on all supported Windows versions, including those updated with the July 2026 Patch Tuesday. The researcher claims the original version did not require additional credentials and could target any registry hive, raising concerns about potential misuse. This disclosure follows an ongoing dispute between the researcher and Microsoft over responsible vulnerability disclosure.