Topic: windows zero-day

  • Unofficial patch fixes Windows LegacyHive zero-day flaw

    Unofficial patch fixes Windows LegacyHive zero-day flaw

    A Windows zero-day vulnerability called LegacyHive in the User Profile Service allows non-admin users to escalate privileges and gain code execution when an administrator logs in, affecting fully updated Windows systems. Microsoft is investigating the flaw but has not yet released an official pat...

    Read More »
  • Windows LegacyHive zero-day grants hackers admin access

    Windows LegacyHive zero-day grants hackers admin access

    Security researcher "Nightmare Eclipse" released a Windows zero-day exploit called LegacyHive that grants elevated privileges on fully patched systems, targeting a flaw in the Windows User Profile Service. The exploit requires additional user credentials to activate, allowing non-admin users to m...

    Read More »
  • New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live

    New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live

    A newly disclosed Windows zero-day exploit called ‘RoguePlanet’ targets a race condition in Microsoft Defender, enabling local privilege escalation to SYSTEM-level access. The exploit allows an attacker with limited privileges to execute code with elevated permissions, bypassing security boundari...

    Read More »
  • Windows MiniPlasma zero-day exploit grants full SYSTEM access, PoC out

    Windows MiniPlasma zero-day exploit grants full SYSTEM access, PoC out

    A security researcher released a working "MiniPlasma" exploit for a Windows zero-day in the Cloud Filter driver (cldflt.sys), granting SYSTEM-level access on fully patched Windows 11 systems. The exploit abuses an unpatched flaw originally reported in 2020 (CVE-2020-17103), allowing arbitrary reg...

    Read More »