Windows LegacyHive zero-day flaw gets free, unofficial patches

Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial micropatches are available for LegacyHive, a Windows zero-day in the User Profile Service that can let non-admin attackers escalate privileges and trigger code execution when an administrator logs in. The flaw was disclosed by Nightmare Eclipse, confirmed by researchers and Kevin Beaumont, and Microsoft says it is investigating while ACROS Security’s 0Patch offers protection for supported Windows versions. #LegacyHive #NightmareEclipse #0Patch #MicrosoftDefenderForEndpoint

Keypoints

  • LegacyHive is a Windows zero-day privilege escalation flaw.
  • The bug was found in the Windows User Profile Service.
  • Non-admin users can modify the classes registry hive through the exploit.
  • ACROS Security released free unofficial micropatches through 0Patch.
  • Nightmare Eclipse has disclosed several other Windows and Microsoft zero-days.

Read More: https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/