Zero‑Day Windows User Profile Service Flaw (LegacyHive) Grants Admin Privileges
What Happened — A researcher identified a previously unknown vulnerability in the Windows User Profile Service (dubbed “LegacyHive”). The exploit, released hours after Microsoft’s July 2026 Patch Tuesday, allows a non‑admin user who also possesses a standard credential to mount another user’s hive and achieve code execution when an administrator logs in. No CVE ID has been assigned yet.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access Controls): an attacker can bypass intended least‑privilege boundaries.
- Continuous‑compliance programs must capture privileged‑access changes in real time to provide audit‑ready evidence.
- Verisq’s SOC 2 Access Controls capability automates collection of privileged‑access logs and validates policy enforcement across Windows endpoints.
Who Is Affected – Enterprises that run Windows workstations or servers, spanning finance, healthcare, SaaS, and government sectors.
Recommended Actions –
- Verify that the latest July 2026 patches are applied to all Windows endpoints.
- Enable and tune detection rules in Microsoft Defender for Endpoint (or equivalent) for the published LegacyHive queries.
- Review and tighten privileged‑access policies (least‑privilege, just‑in‑time elevation) and ensure they are continuously monitored and logged.
Source: BleepingComputer
Technical Notes – The exploit abuses a flaw in the User Profile Service that permits mounting another user’s hive without admin rights, leading to registry manipulation and automatic code execution on admin logon. No CVE ID yet; detection signatures are available for Microsoft Defender for Endpoint. Source: same as above