Windows 0-day drops the same day Microsoft releases record number of patches

A pseudonymous researcher has released a zero-day exploit for Windows, known as HiveLegacy, shortly after Microsoft issued a record number of security patches. The exploit allows low-privilege users to gain administrative-level access by modifying registry hives.
Why it matters
This highlights the persistent vulnerability of enterprise software and the ongoing tension between security researchers and software vendors regarding disclosure practices.
NIGHTMARE ECLIPSE STRIKES AGAIN Windows 0-day drops the same day Microsoft releases record number of patches HiveLegacy is a “powerful primitive” that’s likely capable of other nefarious actions.
8 Credit: Getty Images Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in