LegacyHive zero-day targets the Windows User Profile Service (ProfSvc), leveraging NT AUTHORITY\SYSTEM context and symlink handling during UsrClass.dat loading.
The vulnerability currently has no CVE identifier or official Microsoft security patch.
Free 0patch micropatches are available for supported Windows client and server versions.
Organizations should strengthen endpoint visibility, monitor registry hive activity for suspicious behavior, and prepare for Microsoft’s official security update.
The LegacyHive zero-day has introduced a familiar challenge for enterprise security teams: a publicly disclosed Windows privilege-escalation vulnerability without an official Microsoft security update or CVE identifier. While Microsoft has acknowledged the reported issue and is investigating it, organizations must decide whether to rely on compensating controls, adopt an unofficial mitigation, or wait for a vendor-issued fix.
The vulnerability affects the Windows User Profile Service (ProfSvc) and leverages NT AUTHORITY\SYSTEM context together with symbolic link (symlink) handling during UsrClass.dat loading. According to ACROS Security, a local attacker with standard user privileges could mount another user’s registry hive with full access.
Although exploitation requires prior local access and the publicly released proof of concept has been intentionally limited to make weaponization more difficult, the disclosure highlights why organizations should continue monitoring post-compromise techniques alongside routine patch management.
Why LegacyHive demands attention despite requiring local access
Many Windows privilege-escalation vulnerabilities become significant after an attacker gains an initial foothold. LegacyHive fits this pattern.
According to ACROS Security, the proof of concept allows a standard user to mount the targeted user’s UsrClass.dat registry hive under the attacker’s HKEY_CLASSES_ROOT with full access. An attacker could extract stored secrets or modify registry values that affect what executes when the targeted user signs in. The publicly released proof of concept was intentionally limited to make weaponization more difficult, while Microsoft continues to investigate the reported vulnerability.
This does not automatically translate into full system compromise. Public analysis describes the exploit as a local privilege-escalation primitive that is more useful when combined with other post-compromise techniques than as a complete compromise on its own.
Cybersecurity essentials for any organization
Learn cybersecurity essentials to strengthen organizational resilience and protect enterprise digital assets.
What makes the Windows User Profile Service the focus
The reported vulnerability resides within the Windows User Profile Service (ProfSvc).
Windows uses this service to load and manage user profiles during sign-in, including user-specific registry hives. According to ACROS Security, LegacyHive abuses this behavior by allowing another user’s registry hive to be mounted with full access. If successful, an attacker may modify registry values that influence what runs when the targeted user signs in.
The issue reportedly affects fully updated supported Windows 10 (version 2004 and later) and supported Windows Server systems, meaning organizations cannot rely solely on the latest Patch Tuesday updates.
Provides an interim mitigation for supported versions
Evaluate according to organizational patch policies
Local privilege escalation
Valuable for post-compromise activity
Monitor registry hive activity and privilege-escalation behavior
Targets Windows User Profile Service
Affects endpoint security
Review Windows hardening and endpoint monitoring practices
Interim Mitigation Options While Waiting for Microsoft
Until Microsoft releases an official update, organizations should evaluate temporary risk reduction measures based on their operational requirements.
Evaluate 0patch micropatches
ACROS Security has released free micropatches for Windows 10 version 2004 and later and Windows Server 2022 and later, which are the supported platforms covered by its interim mitigation.
According to ACROS Security, the micropatch loads a temporary user profile hive instead of the targeted user’s hive, preventing the reported exploitation technique. Validate unofficial patches through your organization’s standard change-management process before broad deployment.
Disclaimer: 0patch is an unofficial third-party mitigation from ACROS Security and should be evaluated according to your organization’s change-management policies before deployment.
Strengthen Windows hardening
Reduce unnecessary local privileges, limit interactive access, and enforce least-privilege configurations to reduce opportunities for local privilege-escalation attacks after initial access.
Monitor for suspicious registry activity
Watch for unusual registry hive loading and privilege-escalation behavior, and review available Microsoft Defender for Endpoint detection queries where applicable. Organizations using Microsoft Defender for Endpoint can also review the detection queries published by Kevin Beaumont following the public disclosure.
How Hexnode Supports Enterprise Response
The LegacyHive zero-day primarily affects Windows endpoints, making it most relevant to Hexnode UEM, with complementary support from Hexnode XDR.
Inventory Windows devices running affected operating system versions.
Support UEM patch management by deploying Windows updates and monitoring patch deployment status after Microsoft releases an official update.
Enforce Windows security and configuration policies that support organizational Windows hardening requirements.
Maintain endpoint visibility across managed Windows devices.
With Hexnode XDR, security teams can:
Investigate suspicious endpoint behavior on managed Windows devices.
Support investigations into suspicious endpoint activity using endpoint telemetry and investigation tools.
Correlate endpoint telemetry to assist broader incident investigations.
Hexnode complements Microsoft’s remediation efforts by improving endpoint visibility and investigation workflows but does not replace Microsoft’s security updates or vulnerability remediation.
Featured resource
Introduction to Hexnode XDR
Strengthen endpoint security with Hexnode XDR's unified threat detection, investigation, and response capabilities across enterprise devices.
The LegacyHive zero-day shows why timely patching alone is not enough. Until an official fix is available, organizations should strengthen endpoint security, apply Windows hardening, and monitor for suspicious registry activity.
While Microsoft investigates the issue, security teams should evaluate interim mitigations such as 0patch where appropriate and prepare to deploy the official security update. Combining endpoint visibility, UEM patch management, and security monitoring supports a more effective response to vulnerabilities like LegacyHive.
Stay ahead of Windows security risks
Start your free Hexnode trial for stronger endpoint visibility and management.
LegacyHive is a reported Windows privilege-escalation vulnerability affecting the Windows User Profile Service. It has no CVE identifier, and Microsoft is investigating the issue.
Is there an official Microsoft patch for LegacyHive?
No. Microsoft is investigating the reported vulnerability but has not released an official security update. Free 0patch micropatches are available for supported Windows versions.
What should organizations prioritize first?
Organizations should identify affected Windows endpoints, strengthen monitoring, review Windows hardening, evaluate interim mitigations, and prepare to deploy Microsoft’s official patch when available.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.