Skip to content
LegacyHive exploit targets Windows User Profile Service after July updates

LegacyHive exploit targets Windows User Profile Service after July updates

Feeds.4Sysops IT News July 15, 2026

A security researcher has released a proof-of-concept exploit named LegacyHive that targets the Windows User Profile Service (ProfSvc). This vulnerability allows for local elevation of privileges by forcing the system-level service to load arbitrary registry hives. The exploit remains functional on all currently supported versions of Windows desktop and server, even after applying the July 2026 Patch Tuesday updates. Source

Extracted Entities

Platforms (1)

Vulnerabilities (1)