
New Windows Zero-Day Exploit 'LegacyHive' Allows Admin-Level Privilege Escalation
SecurityMicrosoftZeroDayVulnerabilityPrivilegeEscalationWindows
A security researcher known as 'Nightmare Eclipse' disclosed a Windows zero-day exploit named LegacyHive that enables privilege escalation to admin-level access on fully updated Windows systems. The flaw targets the LegacyHive component, though no specific CVE identifier or affected Windows versions were provided. The exploit allows attackers to bypass security controls and gain elevated privileges without requiring prior authentication. No patch or mitigation steps were mentioned in the disclosure. The impact is limited to local exploitation, meaning attackers must already have some level of access to the target system. The vulnerability was publicly released without prior coordination with Microsoft.