Windows gap: Hackers dupe Microsoft with ninth zero-day exploit

The conflict between the ‘security researcher’ Nightmare Eclipse and Microsoft continues to escalate. Shortly after the latest patch Tuesday, the developer published a new zero-day vulnerability for Windows that allows extensive system access.
New Windows exploit released
A now infamous ‘security researcher’ has made good on his previous threat to Microsoft. Just a few hours after the extensive July patch day, the developer published another zero-day vulnerability for Windows after several holes. The code targets the Windows User Profile Service and enables local privilege escalation on affected systems.
The vulnerability is called LegacyHive and affects the way the operating system loads user-specific registry databases at system startup. If an attack is successful, a standard user can mount another account’s settings into their own session. In a worst-case scenario, this grants read and write access to an administrator’s data, which can make a complete system takeover easier.
The one from Nightmare Eclipse published proof of concept was deliberately severely restricted. The public version requires additional credentials and is limited to a specific file. According to the developer, the full exploit should work without these hurdles and can load any data.
Exact timing
The attacked system service is essential for the correct provision of user profiles after registration. Because it runs with high system privileges, it represents an attractive target for attackers. Zero-day vulnerabilities like LegacyHive are particularly critical because they become known to the public and potential criminals before the manufacturer has been able to develop a working protection. The current release right after the July patch day is no coincidence.
There is a personal conflict behind this. The developer accuses Microsoft of not taking him seriously and not fairly remunerating the security holes he submitted. After a series of bans on developer platforms such as GitHub and GitLab, Nightmare Eclipse threatened to release the zero-day exploit immediately after a patch day at the end of May.
Danger to patched systems
The particularly treacherous thing about LegacyHive is its supposed effectiveness on all currently supported versions of Windows, even if the latest security update is installed. IT security teams warn that skilled attackers could quickly reconstruct the missing parts of the code. In the past, similar gaps were actively exploited by the researcher within a few days. A small bright spot in the current situation is that the restricted published code at least prevents simple free riders from immediate attacks.
Nevertheless, the approach puts Microsoft under a lot of pressure because there is no official patch yet. The company is currently investigating the incident and, as in the past, emphasizes the importance of coordinated disclosure of vulnerabilities in order not to unnecessarily endanger end users.