From 8aea0d33ad024dc131e56ad5dd6553b3849176a0 Mon Sep 17 00:00:00 2001 From: Nightmare-Eclipse Date: Tue, 14 Jul 2026 19:41:33 +0200 Subject: [PATCH] Update README.md --- README.md | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 0c2816c..216a017 100644 --- a/README.md +++ b/README.md @@ -1 +1,10 @@ -# N/A +# LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability + +The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root. + +The PoC was stripped down as an attempt to prevent public exploitation, the original PoC did not require additional user credential and was not limited to usrclass.dat hive, any hive could be loaded using this vulnerability but you would need some brain cells to make the PoC do it. + +Screenshot 2026-07-14 102705 + +The PoC is fully functional in all currently supported desktop and server installation with July 2026 patch. +