Researcher Drops Ninth Windows Zero-Day Exploit Amid Record Patch Tuesday

A pseudonymous researcher going by the name NightmareEclypse releases yet another Windows zero-day exploit, marking the ninth such disclosure from this individual. The latest exploit, dubbed HiveLegacy, targets a vulnerability in the Windows User Profile Service and enables users with limited system privileges to compromise administrator accounts. The drop coincides with Microsoft shipping a record number of security patches in its latest Patch Tuesday update.

HiveLegacy works by allowing low-privilege accounts to modify the classes registry hive of an administrator user, a resource that controls which applications open specific file types in Windows Explorer. Security researchers confirm the exploit functions as described. Will Dormann, a senior principal vulnerability analyst at Tharros Labs, calls the ability to modify an admin user's registry hive "a pretty powerful primitive" that clever attackers can easily leverage for more impactful actions without requiring user interaction.

The exploit arrives amid growing frustration from NightmareEclypse over Microsoft's handling of bug reports. As written, the proof-of-concept code requires the attacker to possess another user's credentials and know the username of a third account on the machine. However, researchers warn that the underlying vulnerability likely enables a broader range of malicious activities, leaving Microsoft scrambling once again to develop and release a fix.

Read More at the original source →