Windows zero-day lets attackers hijack user accounts
A newly found Windows flaw lets attackers hijack user accounts by tricking the system into loading fake account files. Microsoft has not yet patched it.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- Microsoft
- Exploited
- Not confirmedNo confirmation recorded
How it works
An attacker sends a specially crafted file that tricks Windows into loading fake user account data, letting them take over the account.
What to do
Check whether the installed Microsoft version is older than the fixed version in the vendor advisory or current release.
Update Windows immediately through the normal update tool.' Microsoft has not yet fixed this flaw, so wait for their official patch.
Technical details
A critical zero-day vulnerability in Windows allows attackers to hijack user accounts by exploiting the Windows User Profile Service (ProfSvc), a core system component managing user profiles and permissions. Dubbed LegacyHive, the flaw enables arbitrary hive file loading, granting attackers elevated privileges, effectively taking over affected accounts. The proof-of-concept was published by researcher Chaotic Eclipse (Nightmare-Eclipse) under identifier NEWS-bbee8814f8d02d2c33. No fixed versions or CVSS score were disclosed in the source.