{"id":3111,"date":"2026-08-03T03:38:17","date_gmt":"2026-08-03T03:38:17","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=3111"},"modified":"2026-08-03T03:38:17","modified_gmt":"2026-08-03T03:38:17","slug":"windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=3111","title":{"rendered":"Windows 0-day drops the same day Microsoft releases record number of patches"},"content":{"rendered":"<p>Right on the heels of Microsoft releasing a <a href=\"https:\/\/krebsonsecurity.com\/2026\/07\/microsoft-patches-a-record-570-security-flaws\/\">record number<\/a> of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts.<\/p>\n<p>The exploit, which multiple researchers <a href=\"https:\/\/infosec.exchange\/@wdormann\/116925149776495861\">say<\/a> <a href=\"https:\/\/infosec.exchange\/@GossiTheDog@cyberplace.social\/116924831427611458\">works<\/a>, is sending Microsoft scrambling, yet again, to patch a zero-day released by an anonymous researcher who has complained about the software maker\u2019s handling of their bug reports. To date, the pseudonymous NightmareEclypse has published nine such exploits, including <a href=\"https:\/\/blog.projectnightcrawler.dev\/posts\/2026-07-14-legacyhive-public-disclosure\/\">Tuesday\u2019s HiveLegacy<\/a>. The researcher said the proof-of-concept code included in the report was stripped down to prevent attackers from using it maliciously.<\/p>\n<h2>A \u201cpretty powerful primitive\u201d<\/h2>\n<p>HiveLegacy is an elevation-of-privilege exploit that targets a vulnerability residing in the Windows User Profile Service. It allows users (and with more work likely processes) with limited system rights to compromise an admin user&#8217;s account by modifying its <a href=\"https:\/\/learn.microsoft.com\/en-us\/troubleshoot\/windows-server\/performance\/windows-registry-advanced-users\">classes registry hive<\/a>, a resource that ensures the correct application opens when certain types of files are clicked on in Windows Explorer.<\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2026\/07\/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches\/\">Read full article<\/a><\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2026\/07\/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches\/#comments\">Comments<\/a><\/p>\n<p><em>Source: <a href='https:\/\/arstechnica.com\/security\/2026\/07\/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches\/' target='_blank'>Read the original article on arstechnica.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts. The exploit, which multiple researchers say works, is sending Microsoft scrambling, yet again, to patch a zero-day released by an anonymous researcher who [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3112,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,3],"tags":[25,29,33],"class_list":["post-3111","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-share-suggestions","category-technology","tag-impact-msft","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3111"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3111\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/3112"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}